How the campaign worked
The group, known as TA419, posed as AI industry specialists and a former White House official. Its targets included AI policy experts at US think tanks, universities and law firms.
The attackers began with plausible invitations: join a fictional “AI Policy Advisory Board” or contribute to a fake Senate Foreign Relations Committee report. After several emails, they sent infected documents intended to compromise recipients’ cloud accounts.
In one case, an attacker posing as a senior Anthropic employee contacted a think-tank expert with the subject line “Request for comment on Claude’s military integration.”
Proofpoint researcher Mark Kelly told CNN the company was confident the group was linked to the Chinese government. He cited the targets’ alignment with Chinese government interests, infrastructure and technical evidence, as well as corroboration from industry partners.
The attackers also used the name of Lynne Edwards Parker, who served as deputy director of the White House Office of Science and Technology Policy under Joe Biden. Parker told CNN she was concerned for her colleagues and saddened that the attackers were exploiting relationships she had built over her career to deceive others.
The policy fight behind the targeting
The report lands amid a contested debate over AI regulation in the US. Many Americans favor regulation, as do some technology executives, including Anthropic CEO Dario Amodei. They have urged the government to set rules for the industry, warning that uncontrolled AI could threaten safety and infrastructure, or even lead to Armageddon.
The White House opposes those calls, alongside industry figures including Meta’s Mark Zuckerberg and Nvidia’s Jensen Huang. This week, the administration held an unusual summit where AI industry representatives signed a document President Donald Trump called a “morally binding” agreement that would let the industry “engage in broad self-regulation.”
Trump and other opponents of regulation argue that the US cannot afford to fall behind China in the international AI race. Trump recently wrote on Truth Social: “WHOEVER WINS AI, WINS!”
What Proofpoint expects next
Proofpoint expects TA419 to keep targeting think tanks and policy experts working on technologies and in regions of particular interest to the Chinese government. The company also expects the group to continue impersonating real specialists.
I think the most revealing detail is not the Claude subject line by itself, but how the campaign borrows the trust built around policy work: an invitation, a familiar name, then a document. The announcement says little about whether the targeted organizations’ cloud accounts were actually compromised. That gap matters: the operation’s reach is clear, but its impact is not.
Daily AI news
Every day we pick what actually matters in AI and explain it plainly — no hype, no filler. Subscribe if you want to follow where the industry is going.
Only what matters — every day
Follow on X