Published: · Region: Global · Category: cyber

Chinese Hackers Impersonated U.S. AI Experts to Phish AI Policy Staff, Proofpoint Says

Cybersecurity firm Proofpoint says a Chinese group posed as AI researchers and former officials in phishing emails to fewer than 10 people involved in U.S. AI policy and export controls.

A Chinese cyber group has been targeting a small circle of people involved in U.S. artificial intelligence policy by posing as well‑known AI experts and former officials, according to security company Proofpoint.

Proofpoint says the hackers sent carefully crafted emails that appeared to come from prominent figures in AI and national security. The messages offered collaboration or asked for input on AI governance, but the links led to websites built to steal passwords.

Fewer than 10 people were targeted, Proofpoint reports. Even so, they occupy sensitive roles shaping rules on AI models, regulation and export controls. Access to their accounts could offer an early look at draft policies, internal debates and planned restrictions.

The firm says the tactics and technical signatures match previous campaigns linked to Chinese state‑aligned hackers that went after think tanks, government agencies and universities involved in U.S. strategy toward China.

For the victims, the campaign turns their own reputations into attack tools, as their names and profiles are mimicked to increase the chances that colleagues will click. It also raises the bar for routine professional outreach, forcing policymakers and researchers to treat unsolicited invitations with more suspicion.

At a strategic level, the incident shows how AI governance has become a priority target in the wider U.S.–China rivalry. Insight into how Washington plans to police advanced chips, cloud access and powerful models can be as valuable to Beijing as more traditional forms of industrial espionage.

Next steps to watch include whether U.S. agencies or congressional committees address the campaign publicly, whether security guidance for AI and export‑control staff changes, and if similar attacks are detected against officials and researchers working on AI rules in allied countries.

Sources