
BEIJING/WASHINGTON, October 2, 2026: A cyber campaign targeting U.S. and Japanese artificial-intelligence policy experts has used emails impersonating prominent AI specialists, according to cybersecurity company Proofpoint. Reuters reported that the campaign sought to steal passwords and access sensitive email accounts belonging to people working on AI regulation, export controls and national AI strategy.
Proofpoint identified the suspected group as TA419 and attributed the activity to China based on the malware, internet infrastructure and targeting patterns observed by its researchers. Beijing has long denied conducting cyber-espionage operations, and the Chinese Embassy in Washington had not immediately responded to Reuters’ request for comment when the report was published. citeturn1news0
How the phishing campaign worked
According to Proofpoint, attackers sent messages that appeared to come from real experts in artificial intelligence or statecraft. The emails proposed AI-related collaborations or projects and then directed recipients toward websites designed to capture passwords.
The technique is a form of phishing, in which attackers attempt to persuade a target to voluntarily enter credentials or other information into a fraudulent website.
Former White House official impersonated
One of the identities allegedly used in the campaign belonged to Lynne Parker, a former principal deputy director of the White House Office of Science and Technology Policy. The emails were designed to appear connected to AI-policy initiatives.
Reuters independently identified Alex Engler, a former White House official who now heads the Penn Center on Media, Technology, and Democracy, as one person who received a suspicious message. Engler said the email appeared slightly unusual and that he confirmed with others in the field that it was an impersonation. citeturn1news0
Who was targeted?
Proofpoint said the campaign targeted a small number of people at U.S. and Japanese think tanks, universities, defense contractors and law firms. The targets worked on areas including AI regulation, export controls and national AI strategy.
Proofpoint said it had observed fewer than 10 individuals across a handful of organizations in the campaign described in its report.
Why AI policy experts are valuable targets
Artificial intelligence has become a major economic and national-security issue. Governments are developing rules for advanced models, semiconductor exports, data centers and AI safety. Researchers and policy specialists can therefore have access to information about regulatory discussions and strategic priorities.
Intelligence collection versus technology theft
Proofpoint assessed that the pattern of targeting suggested an intelligence interest in U.S. AI policymaking rather than technology theft alone. That assessment is attributed to the cybersecurity company and does not establish the identity or ultimate objectives of the people behind every individual message.
China’s position
Beijing has repeatedly denied accusations that China conducts cyber-espionage operations. The latest report describes an attribution made by Proofpoint based on technical and targeting evidence. The Chinese government had not publicly accepted responsibility for the activity at the time of publication.
Why impersonation works
Impersonation attacks exploit trust. A message that appears to come from a known researcher, government official or professional contact can make a recipient more likely to open an attachment, click a link or begin a conversation.
How organizations can reduce the risk
Security specialists generally recommend multifactor authentication, password managers, phishing-resistant login methods, domain protection and verification of unexpected requests through a separate communication channel. Organizations working on sensitive AI or national-security topics can also benefit from additional monitoring of targeted accounts.
AI is changing the cyber threat landscape
The campaign comes amid broader concern that artificial intelligence is making cyber operations faster and more sophisticated. At the same time, governments and cybersecurity companies are developing AI-based defenses to identify suspicious behavior and protect systems.
Why this matters for the AI industry
AI companies and research institutions hold valuable intellectual property and policy information. Protecting model weights, research data, employee credentials and confidential communications has therefore become an increasingly important part of AI security.
What investigators will watch
Cybersecurity researchers will continue examining the infrastructure used in the campaign, the malware involved and additional targets. New technical evidence could strengthen or change assessments about who conducted the operation and what information they sought.
What happens next
Organizations involved in AI policy and research are likely to increase awareness of impersonation attempts and credential theft. Governments may also continue discussing cybersecurity protections alongside broader AI regulation and technology competition.
NewsNationOnline will continue coverage through its Technology section, International section and Political section. Readers can also consult the U.S. Cybersecurity and Infrastructure Security Agency for cybersecurity guidance.
Source note: The attribution of the campaign to a China-linked group comes from Proofpoint and is reported by Reuters. Beijing has denied cyber-espionage allegations generally. The article does not independently attribute the operation to the Chinese government.
