Fake Anthropic Staffers Phished US AI Policy Experts

Threat assessment: elevated. A hacking group that appears to be backed by China has been posing as Anthropic researchers and former White House officials to get into the accounts of American AI policy experts. Futurism AI reports that the campaign comes from a group called “TA419,” which the Silicon Valley security firm Proofpoint identified in a new report. The targets weren’t AI labs. They were the people around them: “AI policy experts at US think tanks, universities, and law firms.”

What stands out is how ordinary the bait looked. Nobody got a crude phishing email. They got invitations that sounded like normal career opportunities.

🎯 How the operation worked

As detailed in Futurism AI, the attack followed a patient, step-by-step playbook:

  1. The first message. The hackers sent friendly intro emails inviting experts to join a made-up “AI Policy Advisory Committee” or to contribute to a fictional Senate Committee on Foreign Relations report.
  2. Building trust. They traded a few emails with each target before attempting anything malicious.
  3. The payload. Once the target was comfortable, the group sent documents laced with malware, designed to break into the target’s cloud accounts.

One email stands out. Hackers posing as a senior Anthropic staffer sent a think tank employee a message with the subject line “Request for Feedback on Military Integration of Claude.” That’s a well-chosen lure. It’s specific and timely, and it’s exactly the kind of request a policy researcher would want to answer.

🕵️ Who’s behind it

Proofpoint researcher Mark Kelly told CNN the firm is “confident” the group is a “Chinese government-aligned threat actor based on targeting consistently in line with Chinese government interests, observed infrastructure and technical artifacts, and corroboration from industry partners.”

The hackers also impersonated real people. One of them was Lynne Edwards Parker, who served as Principal Deputy Director of the White House Office of Science and Technology Policy under President Biden. She told CNN that, besides worrying about her colleagues, she felt “sadness that relationships I’ve built over my career were being exploited by bad actors to deceive others.”

That line points to the real damage here. The attackers weren’t only stealing data. They were spending the trust that real experts have built up over years.

📡 Why this matters

This is significant because it shows where AI espionage is heading. Breaking into frontier labs directly is hard. Their security teams are big and on alert. The policy layer around them is a softer target. Think tanks, academics, and law firms often see early drafts, internal debates, and strategy thinking well before any of it becomes public.

The timing makes it sharper. US AI policy is in a tense spot right now:

  • The push to regulate. Most Americans support AI regulation, and so do some leading executives, with Anthropic’s Dario Amodei the most prominent among them.
  • The pushback. The White House, along with figures like Meta’s Mark Zuckerberg and Nvidia’s Jensen Huang, has resisted those calls. This week, the administration hosted a summit where industry leaders signed what President Trump called a “morally-binding” agreement that would allow for “tremendous self-policing.”
  • The China argument. The main case against regulation is that the US can’t afford to lose the AI race to China. “Whoever wins AI, WINS!” Trump posted on Truth Social.

That creates an irony. The same rivalry used to argue for moving fast is now showing up as active intelligence operations aimed at the people shaping US policy.

🛡️ Tactical guidance for practitioners

If you work anywhere near AI policy, research, or advisory work, assume you’re a potential target. Here’s what to tighten up:

  1. Verify identities through a separate channel. If a “senior researcher” emails you, confirm it through a known phone number or a mutual contact. Don’t just reply to the thread.
  2. Be wary of flattering invitations. Advisory committees and Senate report contributions are exactly the kind of offers that get people to lower their guard.
  3. Treat documents with suspicion, even late in a conversation. This campaign deliberately built rapport before sending anything malicious. A friendly thread with three earlier emails doesn’t make an attachment safe.
  4. Lock down cloud accounts. Use hardware security keys or phishing-resistant multi-factor authentication. The whole point of the malware was to get into cloud accounts.
  5. Report impersonation fast. If someone is pretending to be you, warn your network quickly so the damage stays small.

🔭 What comes next

Proofpoint expects TA419 to “likely continue targeting think tanks and policy experts working on technologies, and in geographies, of particular interest to the Chinese government.” The firm added that “these campaigns will likely also continue spoofing the identities of real subject-matter experts.”

In other words, this isn’t a one-off. The more AI policy matters, the more valuable the people writing it become as targets. Expect more campaigns like this, more convincing impersonations, and more pressure on think tanks and universities to protect themselves the way the labs already do. Full details are available in the original Futurism AI report.

Scroll to Top