China-linked hackers posed as former US officials, Anthropic employee to target AI experts与中国有关联的黑客冒充美国前官员和人科研究所员工,攻击人工智能专家。
Proofpoint identified phishing campaigns that borrowed prominent figures’ identities to approach U.S. policy researchers before attempting to steal access to their cloud accounts.

szakalikus / Getty Images
Proofpoint identified phishing campaigns that borrowed prominent figures’ identities to approach U.S. policy researchers before attempting to steal access to their cloud accounts.
Artificial Intelligence
Chinese hackers impersonated a former senior White House technology official, a former State Department economist and a senior Anthropic employee in attempts to break into the cloud accounts of artificial intelligence policy experts, according to findings from cybersecurity company Proofpoint released Thursday.
The campaigns targeted researchers at think tanks, universities and law firms, using invitations to advise on AI policy and export controls to start conversations. Once recipients responded, the attackers sent links designed to steal their Microsoft login credentials, per the findings.
Among those impersonated were Lynne Parker, a former principal deputy director of the White House Office of Science and Technology Policy, and Heidi Crebo-Rediker, who served as the State Department’s first chief economist.
Proofpoint connected the activity to a group tracked as TA419, describing it as a China-aligned outfit supporting Beijing’s intelligence interests. The report doesn’t say how many people were targeted, whether any accounts were successfully compromised or if the attackers obtained any information.
Beginning July 8, the hackers posed as Parker and then Crebo-Rediker in messages inviting AI experts to join a fictitious “AI Policy Advisory Committee” or contribute to a purported Senate Foreign Relations Committee report on AI export controls and supply chains. Parker’s White House roles included assistant director for AI and founding director of the National AI Initiative Office. Crebo-Rediker, now a Council on Foreign Relations senior fellow, previously worked as the Senate Foreign Relations Committee’s chief of international finance and economics.
After a recipient engaged with the initial messages, the attackers followed up with correspondence that directed targets to a fake OneDrive page used to attempt the account theft.
The group had also used a similar approach in February, impersonating a senior Anthropic employee in an email to an AI policy analyst at a U.S. think tank, Proofpoint said. The subject line read, “Request for Feedback on Military Integration of Claude,” invoking ongoing debate over military use of the company’s AI models. The research did not name the impersonated employee.
The hackers have “consistently shown an interest in defense, national security, energy, international relations, and foreign policy targets, predominantly with a nexus to the U.S. and Japan,” the report says. “The targeting of AI policy experts represents an extension of that remit rather than a departure from it.”
In an email to Nextgov/FCW , Parker confirmed that she learned of the impersonation on July 9, when two recipients contacted her through separate channels to ask whether she had sent the emails. She told them the messages were fraudulent and alerted other colleagues.
“The challenge is that, without knowing who the bad actors are targeting, it’s difficult to reach everyone who might be at risk,” Parker said.
“It is personally troubling to see the trust and relationships I’ve built over my career exploited to deceive others,” she added. “Targeting people in the field can be a way to gain access to valuable information and networks. Protecting America’s AI leadership requires protecting the people and institutions behind it and recognizing that trusted relationships can themselves become a target.”
Crebo-Rediker and Anthropic did not respond to requests for comment. China’s embassy in Washington, D.C., was also contacted. Chinese officials have routinely denied allegations of state-backed hacking and espionage.
The decision to target policy researchers highlights expanding intelligence threats in the global AI race between the U.S., China and other nation-states. Access to experts’ accounts could expose private discussions and professional contacts relevant to decisions about AI’s development, military use and sale abroad. The cyberspies’ approach also illustrates how attackers continue to exploit the dynamics of routine professional exchanges for information-gathering.
The findings also come as AI companies gain an increasingly direct role in Washington’s debate over how to oversee the fast-evolving technology. President Donald Trump met with industry leaders Tuesday to endorse voluntary AI safety commitments . Anthropic CEO Dario Amodei also had dinner with Trump on Sunday.
Proofpoint found that the attackers registered web addresses impersonating the Heritage Foundation, Japan’s defense minister Shinjiro Koizumi and the Japan–Taiwan Exchange Association. Posing as those figures and organizations could help the hackers convince experts that a malicious email is worth their time.
“At the end of the day, humans are our best line of defense,” Don Styer, a former Navy Supply Corps officer and executive vice president for federal services at Consulting Solutions, said in an interview. Attackers can exploit trust through impersonation or seemingly routine requests, he said, adding that foreign adversaries value intelligence they can’t find in public sources and may combine seemingly innocuous details to build a larger picture of a target.
Professional outreach has long been used as an intelligence tool. Nextgov/FCW reported in January that a suspected Chinese spying outfit approached a former senior State Department official last year with an offer to pay for research on U.S. policy toward Venezuela.
The International Consortium of Investigative Journalists reported in June that its reporters received suspicious consulting offers after publishing an investigation into China’s transnational repression. Separately, Britain’s MI5 on Wednesday accused the China General Technology Research Institute of funding academic work to improve Chinese intelligence capabilities. Over 100 U.K.-based academics had contributed to its projects, including research involving AI and cybersecurity, according to the agency, which added that many participants may have been unaware of the institute’s intelligence ties.
The targeting comes amid broader U.S. concerns about Chinese efforts to siphon American AI capabilities. Early last month, the NSA and other agencies accused Chinese developers of conducting large-scale distillation campaigns that use responses from advanced U.S. models to train competing systems.
The attackers revealed in Proofpoint’s findings “will likely continue targeting think tanks and policy experts working on technologies, and in geographies, of particular interest to the Chinese government” and will “likely also continue spoofing the identities of real subject-matter experts,” the company said.
NEXT STORY: Pentagon update on National Defense Strategy cites progress, omits key threats
szakalikus / Getty Images
Proofpoint 发现,一些网络钓鱼活动盗用知名人士的身份,接近美国政策研究人员,然后试图窃取其云帐户的访问权限。
人工智能
网络安全公司 Proofpoint 周四发布的调查结果显示,中国黑客冒充了一名前白宫高级技术官员、一名前国务院经济学家和一名 Anthropic 高级员工,试图入侵人工智能政策专家的云账户。
这些攻击活动的目标是智库、大学和律师事务所的研究人员,攻击者以邀请他们就人工智能政策和出口管制提供咨询为由,展开对话。调查结果显示,一旦收件人做出回应,攻击者就会发送旨在窃取其微软登录凭据的链接。
被冒充的人物包括白宫科技政策办公室前首席副主任琳恩·帕克,以及国务院首任首席经济学家海蒂·克雷博-雷迪克。
Proofpoint 将此次攻击活动与一个名为 TA419 的组织联系起来,并称其为支持北京情报利益的亲中组织。报告并未说明有多少人成为攻击目标,是否有账户被成功入侵,以及攻击者是否获取了任何信息。
从7月8日起,黑客冒充帕克和克雷博-雷迪克,向人工智能专家发送信息,邀请他们加入一个虚构的“人工智能政策咨询委员会”,或为一份据称由参议院外交关系委员会撰写的关于人工智能出口管制和供应链的报告提供信息。帕克曾在白宫担任人工智能助理主任和国家人工智能倡议办公室创始主任。克雷博-雷迪克目前是外交关系委员会的高级研究员,此前曾担任参议院外交关系委员会国际金融和经济事务主管。
在收件人回复初始消息后,攻击者会跟进发送邮件,引导目标访问一个伪造的 OneDrive 页面,该页面用于尝试窃取帐户。
Proofpoint公司表示,该组织在今年2月也曾使用过类似手段,冒充Anthropic公司的一名高级员工,向一家美国智库的人工智能政策分析师发送了一封电子邮件。邮件主题为“就Claude的军事整合征求反馈意见”,意在引发关于该公司人工智能模型军事用途的持续争论。该研究并未透露被冒充员工的姓名。
报告称,这些黑客“一直对国防、国家安全、能源、国际关系和外交政策目标表现出浓厚的兴趣,尤其与美国和日本关系密切”。“攻击人工智能政策专家是其攻击范围的延伸,而非偏离。”
帕克在发给 Nextgov/FCW 的一封电子邮件中证实,她于 7 月 9 日得知此事,当时有两名收件人通过不同的渠道联系她,询问她是否发送了这些邮件。她告诉他们这些邮件是诈骗邮件,并提醒了其他同事。
帕克说:“挑战在于,如果不了解不法分子针对的目标是谁,就很难接触到所有可能面临风险的人。”
她补充道:“看到我多年来建立的信任和人脉关系被用来欺骗他人,我个人感到非常痛心。针对业内人士进行攻击,可能成为获取宝贵信息和人脉网络的一种手段。保护美国在人工智能领域的领先地位,需要保护其背后的人员和机构,同时也要认识到,即使是值得信赖的关系本身也可能成为攻击目标。”
Crebo-Rediker 和 Anthropic 公司均未回应置评请求。记者也联系了中国驻华盛顿大使馆。中国官员一贯否认有关国家支持的黑客攻击和间谍活动的指控。
此次针对政策研究人员的行动凸显了美国、中国和其他国家在全球人工智能竞赛中面临的日益严峻的情报威胁。获取专家账户信息可能会泄露与人工智能开发、军事用途和海外销售相关的私人讨论和专业联系。网络间谍的这种做法也表明,攻击者如何持续利用日常专业交流的动态来收集信息。
与此同时,人工智能公司在华盛顿关于如何监管这项快速发展技术的辩论中扮演着越来越直接的角色。周二,唐纳德·特朗普总统会见了行业领袖,支持自愿性人工智能安全承诺。Anthropic首席执行官达里奥·阿莫迪也于周日与特朗普共进晚餐。
Proofpoint发现,攻击者注册了冒充美国传统基金会、日本防卫大臣小泉进次郎以及日台交流协会的网址。冒充这些人物和机构可以帮助黑客说服专家,让他们相信恶意邮件值得他们花费时间。
“归根结底,人类才是我们最好的防线,”前海军后勤部队军官、咨询解决方案公司联邦服务执行副总裁唐·斯泰尔在一次采访中表示。他指出,攻击者可以通过冒充他人或看似例行公事的请求来利用信任,并补充说,外国敌对势力重视那些无法从公开渠道获取的情报,他们可能会将看似无关紧要的细节结合起来,从而构建出目标的完整图景。
专业联络长期以来一直被用作情报工具。Nextgov/FCW 在今年1月报道称,一个疑似中国间谍机构去年曾接触过一位前国务院高级官员,提出付费研究美国对委内瑞拉的政策。
国际调查记者联盟(ICIJ)6月发布报告称,其记者在发表一篇关于中国跨国镇压的调查报道后,收到了可疑的咨询邀约。与此同时,英国军情五处(MI5)周三指控中国通用技术研究院资助学术研究以提升中国的情报能力。军情五处称,超过100名英国学者参与了该研究院的项目,其中包括人工智能和网络安全方面的研究。军情五处还补充说,许多参与者可能并不了解该研究院与情报机构的联系。
此次行动正值美国对中国窃取美国人工智能能力的担忧日益加剧之际。上月初,美国国家安全局和其他机构指责中国开发者开展大规模的“数据提炼”活动,利用美国先进模型的响应数据来训练竞争对手的系统。
Proofpoint 的调查结果显示,攻击者“可能会继续以智库和政策专家为目标,这些专家研究的技术和所在地区对中国政府来说具有特殊意义”,并且“很可能还会继续冒充真正的领域专家的身份”,该公司表示。
下一篇报道:五角大楼发布国家国防战略更新报告,列举进展,却忽略关键威胁