in

China-aligned Hackers Posed as U.S. AI Experts to Steal Policy Emails

Proofpoint this week dropped a technical report that should make every American who cares about national security sit up. The firm says a China‑aligned hacking group it tracks as TA419 ran clever phishing attacks that impersonated U.S. AI experts and a former White House OSTP deputy to steal email and cloud credentials from a small group of AI policy researchers. This is not teenage prankware — it looks like state‑style espionage aimed at shaping the future of U.S. AI policy and keeping score in the tech race.

What Proofpoint found in the TA419 campaign

According to Proofpoint, the campaign targeted fewer than ten people — policy analysts, legal experts, and AI researchers at think tanks, universities, and law firms. The attackers posed as trusted figures and sent tailored invitations to join a fake “AI Policy Advisory Committee” or to contribute to reports. One recipient, Alex Engler, Executive Director of the Penn Center on Media, Technology, and Democracy, called one message “slightly, nebulously off,” which is a polite way of saying it smelled like a setup.

How the hackers stole credentials

The tradecraft was advanced. TA419 used personalized outreach, link shorteners and redirect chains that led victims to sites that looked like legitimate Microsoft sign‑in pages. They employed a Browser‑in‑the‑Browser trick and an adversary‑in‑the‑middle proxy to capture session cookies and sidestep multi‑factor authentication. In plain English: the bad guys stole login sessions, not just passwords. Proofpoint published indicators and technical details so defenders can block the domains and addresses involved — which is helpful, but only part of the fix.

Why this matters for U.S. national security and AI policy

This isn’t just about stolen emails or embarrassing drafts. The targeting of policy experts shows the actor wants to know how the U.S. plans to regulate and control AI — that’s intelligence value, plain and simple. While politicians bicker, foreign adversaries quietly collect the drafts, contact lists, and informal debates that shape policy. If you think stealing model weights is bad, try losing your policymakers’ playbook to a foreign spy. The administration, Congress, and private institutions should treat this like what it is: an escalation in cyber espionage tied to the U.S.–China competition over AI.

What must be done now

Simple steps can cut risk fast: move people off passwords and toward phishing‑resistant options like passkeys and origin‑bound credentials; train staff to treat unsolicited, flattering outreach as potential pretext; verify unexpected requests on a second channel; and block the IoCs Proofpoint provided. Beyond that, federal cyber agencies should be blunt about attribution and push public advisories so institutions can act. If we want to win the tech race, we can’t be surprised by basic espionage tricks — and we sure can’t let policy debates be harvested by foreign intelligence. Wake up, harden up, and stop congratulating each other for “collaboration” while our playbooks get lifted.

Written by Staff Reports

Gen Jack Keane: This is all connected

Keane: Iran Plot at RAF Fairford Signals Growing Threat to US

Supreme Court Set to Give Trump Admin Power to Detain Millions

Supreme Court Set to Give Trump Admin Power to Detain Millions