China-linked hackers impersonated US AI insiders as global race heats up随着全球人工智能竞赛升温,与中国有关联的黑客冒充美国人工智能内部人士。
Suspected Chinese hackers impersonated an Anthropic employee and ex-US officials in an espionage campaign aimed at gaining insights into American AI developments, a US cybersecurity firm said Thursday.

Kylie Cooper/Reuters
Suspected Chinese hackers impersonated an Anthropic employee and ex-US officials in an espionage campaign aimed at gaining insights into American AI developments, a US cybersecurity firm said Thursday.
The hackers targeted the email accounts of experts in AI export controls and the military applications of AI, among other topics, who work at US universities, think tanks and law firms, according to Silicon Valley-based Proofpoint, which discovered the activity.
Access to those experts’ digital lives could offer Beijing critical insights into how US society is grappling with what many see as an existential issue in AI governance.
Proofpoint did not find evidence of successful breaches of the targeted organizations, but the firm may have only uncovered some of the activity, and Beijing-linked groups are known to keep trying on a target until they get in.
“We are confident that [the hacking group] is a Chinese government-aligned threat actor based on targeting consistently in line with Chinese government interests, observed infrastructure and technical artifacts, and corroboration from industry partners,” Proofpoint staff researcher Mark Kelly told CNN in an email.
CNN has requested comment from the Chinese Embassy in Washington, DC. Beijing regularly denies US hacking allegations.
News of the hacking attempts, which occurred in February and July, comes as AI continues to be a crucial focal point in US-China relations.
President Donald Trump discussed AI last week at the White House with Chinese leader Xi Jinping, but the meeting did not produce a substantive accord on the technology. Trump has resisted calls for guardrails on advanced AI models out of concern that the US will fall behind China in the race for AI supremacy.
Last month, the Trump administration accused Chinese AI firms of committing “industrial-scale” theft of their American counterparts’ trade secrets to save money and bring the coveted technology to market faster. China denied the allegations.
US allies have also warned about China’s access to AI know-how. Britain’s MI5 intelligence service said Wednesday that British academics have contributed research on AI and cybersecurity to a Chinese institute with close ties to Chinese intelligence. In some cases, the academics may not have been aware of the connection between the institute and Chinese intelligence, the advisory said.
In the activity Proofpoint uncovered, the suspected Chinese operatives impersonated Lynne Parker, who served as a senior tech official in the White House under Trump and President Joe Biden. The hackers sent an email posing as Parker to someone at a US law firm inviting them to participate in an “AI policy advisory committee.” The fake Parker followed up with a malware-laced document purporting to offer more information on the fake committee.
The real Parker told CNN that colleagues started reaching out to her when they received suspicious emails from people claiming to be her.
“My first concern was for the colleagues who might receive the impersonated email,” said Parker, who is now associate vice chancellor emerita at the University of Tennessee, Knoxville. “I wanted to warn them but realized that’s very difficult to do when I don’t know who is being targeted.”
“On a personal level, I felt sadness that relationships I’ve built over my career were being exploited by bad actors to deceive others,” Parker said in an email.
The suspected Chinese operatives also, according to Proofpoint, chose to impersonate a senior employee at Anthropic, the American AI firm that has clashed with the Trump administration over guardrails on the technology.
The hackers sent an email on February 26 in the name of the Anthropic employee to an AI policy analyst at a US think tank. The subject line read, “Request for Feedback on Military Integration of Claude,” a reference to one of Anthropic’s AI models. Through the email exchange, the hackers tried to steal the think tanker’s email credentials, according to Proofpoint.
The day after the email, the Trump administration ordered federal agencies and contractors that work with the military to cease business with Anthropic after the firm refused to allow the Pentagon to use its artificial-intelligence technology without restrictions.
Chinese cyber operatives, according to experts who track them, are targeting just about every level of the AI ecosystem, from the semiconductors that power the technology to the people who dedicate their careers to it. US competitiveness in AI may hinge on how well it can protect that ecosystem from infiltration, according to experts.
“Getting AI policy right is essential to our national security and economic competitiveness,” said Parker, the former US tech official who was impersonated. “That includes protecting the people and institutions whose expertise helps inform those decisions.”
凯莉·库珀/路透社
一家美国网络安全公司周四表示,疑似中国黑客冒充 Anthropico 公司员工和美国前官员,开展间谍活动,旨在获取美国人工智能发展方面的信息。
据硅谷公司 Proofpoint 发现的这一黑客活动称,黑客们将目标锁定在美国大学、智库和律师事务所工作的专家的电子邮件帐户上,这些专家的研究领域包括人工智能出口管制和人工智能的军事应用等。
了解这些专家的数字生活,可以让北京深入了解美国社会如何应对人工智能治理中许多人眼中的生死攸关的问题。
Proofpoint 没有发现成功入侵目标组织的证据,但该公司可能只发现了部分活动,而且众所周知,与北京有关联的组织会不断尝试攻击目标,直到成功入侵为止。
Proofpoint 的研究员 Mark Kelly 在一封电子邮件中告诉 CNN:“我们确信(该黑客组织)是一个与中国政府结盟的威胁行为者,其攻击目标始终与中国政府的利益保持一致,观察到的基础设施和技术痕迹,以及来自行业合作伙伴的证实,都印证了这一点。”
CNN已向中国驻华盛顿大使馆请求置评。北京方面一贯否认美国提出的黑客指控。
今年2月和7月发生的黑客攻击事件的消息传出之际,人工智能仍然是美中关系的一个关键焦点。
上周,美国总统唐纳德·特朗普在白宫与中国国家主席习近平讨论了人工智能问题,但会晤并未就该技术达成实质性协议。特朗普一直拒绝为先进的人工智能模型设置限制措施,担心美国会在人工智能领域的竞争中落后于中国。
上个月,特朗普政府指责中国人工智能公司“大规模”窃取美国同行的商业机密,以节省成本并更快地将这项炙手可热的技术推向市场。中国否认了这些指控。
美国盟友也对中国获取人工智能技术发出警告。英国军情五处周三表示,一些英国学者曾向一家与中国情报机构关系密切的中国研究机构提供人工智能和网络安全方面的研究成果。该机构的警告称,在某些情况下,这些学者可能并不了解该机构与中国情报机构之间的联系。
在Proofpoint揭露的这起活动中,疑似中国黑客冒充了琳恩·帕克(Lynne Parker)。帕克曾在特朗普和拜登总统执政期间担任白宫高级技术官员。黑客以帕克的名义向一家美国律师事务所的某人发送了一封电子邮件,邀请其参加一个“人工智能政策咨询委员会”。随后,冒充帕克的人又发送了一份植入恶意软件的文件,声称提供了更多关于这个虚假委员会的信息。
真正的帕克告诉 CNN,当同事们收到自称是她本人的可疑电子邮件时,他们开始联系她。
“我首先担心的是那些可能会收到冒充邮件的同事,”帕克说道,他现在是田纳西大学诺克斯维尔分校的荣誉副校长。“我想提醒他们,但意识到在不知道谁是目标的情况下,这很难做到。”
帕克在一封电子邮件中说:“就我个人而言,我感到难过,因为我在职业生涯中建立的人脉关系被一些不法分子利用来欺骗他人。”
据 Proofpoint 称,这些疑似中国特工还选择冒充美国人工智能公司 Anthropic 的一名高级员工。Anthropic 曾因人工智能技术的监管问题与特朗普政府发生冲突。
2月26日,黑客以Anthropic公司一名员工的名义向美国一家智库的人工智能政策分析师发送了一封电子邮件。邮件主题为“请求就Claude的军事整合提供反馈”,Claude是Anthropic公司开发的一款人工智能模型。据Proofpoint公司称,黑客试图通过这封邮件窃取该智库分析师的邮箱账号。
在电子邮件发出后的第二天,特朗普政府下令与军方合作的联邦机构和承包商停止与 Anthropic 公司的业务往来,此前该公司拒绝允许五角大楼在不受限制的情况下使用其人工智能技术。
据追踪中国网络攻击的专家称,中国网络攻击者几乎将目标对准了人工智能生态系统的各个层面,从支撑这项技术的半导体到毕生致力于此的专业人士。专家认为,美国在人工智能领域的竞争力可能取决于其保护该生态系统免受渗透的能力。
“制定正确的AI政策对我们的国家安全和经济竞争力至关重要,”被冒充的美国前科技官员帕克说。“这包括保护那些拥有专业知识、能够为这些决策提供依据的人员和机构。”