Suspected Chinese hackers posed as an Anthropic employee and ex-US officials to spy on AI

Suspected Chinese hackers posed as an Anthropic employee and ex-US officials to spy on AI

Suspected Chinese hackers impersonated an Anthropic employee and former US officials in an espionage campaign aimed at gaining insights into American AI developments, the US cybersecurity firm Proofpoint said on Thursday. Proofpoint, which is based in Silicon Valley and discovered the activity, says the attempts occurred in February and July.

The targets were the email accounts of experts in AI export controls and the military applications of AI, among other topics, who work at US universities, think tanks and law firms. CNN notes that access to those experts' digital lives could give Beijing critical insight into how US society is grappling with what many see as an existential issue in AI governance.

In one lure, the operatives impersonated Lynne Parker, who served as a senior tech official in the White House under Trump and President Joe Biden. A fake Parker emailed someone at a US law firm and invited them to join an "AI policy advisory committee", then followed up with a malware-laced document that purported to offer more information on the fake committee. The real Parker, now associate vice chancellor emerita at the University of Tennessee, Knoxville, told CNN that colleagues began contacting her after receiving suspicious emails from people claiming to be her.

In a second lure, the operatives, according to Proofpoint, impersonated a senior employee at Anthropic. On February 26 they sent an email in that person's name to an AI policy analyst at a US think tank. The subject line read "Request for Feedback on Military Integration of Claude". Through the exchange, the hackers tried to steal the analyst's email credentials, according to Proofpoint. The day after that email, the Trump administration ordered federal agencies and contractors that work with the military to cease business with Anthropic, after the firm refused to allow the Pentagon to use its AI technology without restrictions.

Proofpoint did not find evidence of successful breaches of the targeted organizations. But the firm may have uncovered only some of the activity, and Beijing-linked groups are known to keep trying on a target until they get in. Proofpoint staff researcher Mark Kelly told CNN by email that the firm is confident the group is a Chinese government-aligned threat actor, citing targeting consistent with Chinese government interests, observed infrastructure and technical artifacts, and corroboration from industry partners.

CNN has asked the Chinese Embassy in Washington for comment. China began its weeklong National Day holiday on Thursday, and all government offices are closed. Beijing regularly denies US hacking allegations.

CNN places the news against a wider backdrop. Trump discussed AI with Xi Jinping at the White House last week, but the meeting produced no substantive accord on the technology. Trump has resisted calls for guardrails on advanced AI models out of concern that the US will fall behind China. Last month his administration accused Chinese AI firms of "industrial-scale" theft of American counterparts' trade secrets; China denied it. And on Wednesday Britain's MI5 said British academics have contributed research on AI and cybersecurity to a Chinese institute with close ties to Chinese intelligence, in some cases perhaps without knowing the connection. Experts who track Chinese cyber operatives say they are targeting just about every level of the AI ecosystem, from semiconductors to the people working in AI.

Key facts

  • Proofpoint says suspected Chinese hackers impersonated an Anthropic employee and ex-US officials, including Lynne Parker, in email campaigns in February and July.
  • Targets were experts in AI export controls and military AI at US universities, think tanks and law firms.
  • Lures included an invitation to an "AI policy advisory committee" followed by a malware-laced document, and a February 26 email titled "Request for Feedback on Military Integration of Claude" meant to steal a think-tank analyst's email credentials.
  • Proofpoint found no evidence of successful breaches but may have seen only part of the activity.
  • Proofpoint's Mark Kelly says the firm is confident the group is Chinese government-aligned; Beijing regularly denies US hacking allegations.

Why it matters

The campaign went after the people who shape and debate US AI policy rather than after companies' systems. CNN says access to those experts' digital lives could give Beijing critical insight into how the US is grappling with AI governance. It lands as AI is a central issue in US-China relations: a Trump-Xi discussion last week produced no substantive accord, the Trump administration has accused Chinese AI firms of "industrial-scale" theft of trade secrets, and MI5 has warned about British academics' research reaching a Chinese institute tied to Chinese intelligence. Experts cited by CNN say US competitiveness in AI may hinge on how well it protects its AI ecosystem from infiltration.

Who it affects

Proofpoint says the targets were experts in AI export controls and the military applications of AI, among other topics, at US universities, think tanks and law firms. People whose names were borrowed are affected too. Lynne Parker, the former White House tech official, said her first concern was for colleagues who might receive the impersonated email, and that she found it hard to warn them without knowing who was being targeted. An unnamed senior Anthropic employee was also impersonated, and the lure referred to Claude.

How to use it

The source offers no checklist or tool. What it does show is the shape of the lures: an unsolicited invitation to join an "AI policy advisory committee" followed by a document carrying malware, and a request for feedback on a sensitive topic that was used to try to steal email credentials. Experts in AI policy, and the organizations that employ them, can use those two patterns as concrete examples of what a targeted approach looked like in this case.

How solid is it

The findings come from Proofpoint, the firm that discovered the activity, as relayed by CNN. Attribution is stated with confidence by Proofpoint staff researcher Mark Kelly, who cites targeting in line with Chinese government interests, observed infrastructure and technical artifacts, and corroboration from industry partners. The hacking group is not named in the article, and CNN's request for comment from the Chinese Embassy was still pending. Parker's account of colleagues receiving fake emails is first-hand, given to CNN. The Anthropic employee, the law firm and the think tank are not named.

Risks and caveats

Proofpoint found no evidence of successful breaches, so this is a report of attempts. It also says it may have uncovered only some of the activity, and Beijing-linked groups are known to keep trying until they get in. The article notes that the Trump administration ordered federal agencies and military contractors to cease business with Anthropic the day after the February 26 email, but it does not say the two events are connected. Beijing regularly denies US hacking allegations. The article carries an update note, and the text does not say what was changed.

“Getting AI policy right is essential to our national security and economic competitiveness”

— Lynne Parker, former US tech official who was impersonated