CRBC News
Security

Suspected China-Linked Hackers Posed as Anthropic Staff and Former US Officials to Phish AI Experts

Suspected China-Linked Hackers Posed as Anthropic Staff and Former US Officials to Phish AI Experts
The Embassy of China in Washington D.C., on August 27. - Francis Chung/POLITICO/AP

Proofpoint reported that suspected China-linked hackers impersonated an Anthropic employee and former U.S. officials to target email accounts of AI policy and military-AI specialists in February and July. The campaign used phishing emails and malware-laced documents to try to steal credentials, though no confirmed breaches were disclosed. Investigators say the activity aligns with Chinese government interests and highlights growing U.S.-China tensions over AI governance and security.

Suspected China-linked hackers impersonated an Anthropic employee and former U.S. officials in a targeted espionage campaign aimed at harvesting information about American artificial intelligence developments, cybersecurity firm Proofpoint said Thursday.

The intrusion attempts — observed in February and July — focused on email accounts belonging to specialists in AI export controls, military applications of AI and related policy fields at U.S. universities, think tanks and law firms. Proofpoint said the activity included credential-phishing attempts and distribution of malware-laced documents, though it found no confirmed successful breaches of the targeted organizations.

How the Campaign Worked

Proofpoint’s investigation found attackers sent spoofed emails impersonating high-profile figures, including Lynne Parker, who served as a senior White House technology official under both the Trump and Biden administrations. In one case, the fake Parker invited a law-firm employee to join an "AI policy advisory committee" and followed up with a document that contained malware.

The suspected operatives also posed as a senior Anthropic employee. On Feb. 26 they emailed an AI policy analyst at a U.S. think tank under the subject line, "Request for Feedback on Military Integration of Claude," referencing Anthropic’s AI model, Claude. Proofpoint said the exchange was designed to phish the analyst’s credentials.

Proofpoint staff researcher Mark Kelly told CNN the targeting, technical artifacts and observed infrastructure link the activity to a Chinese government-aligned actor, though the firm cautioned it may have only uncovered part of the campaign.

Context and Consequences

Suspected China-Linked Hackers Posed as Anthropic Staff and Former US Officials to Phish AI Experts
An email from a hacker impersonating Lynne Parker, a former US technology official in the Trump and Biden administrations, to an employee of a US law firm. - Courtesy Proofpoint

The campaign comes amid rising U.S.-China tensions over AI policy, security and commercial competition. The actions were reported shortly after President Donald Trump and Chinese leader Xi Jinping discussed AI at the White House, and just after the Trump administration accused Chinese AI firms of large-scale theft of U.S. trade secrets — allegations China denies.

Notably, the February phishing email to the think tanker preceded a Trump administration order for federal agencies and defense contractors to halt certain work with Anthropic after the company declined to give the Pentagon unrestricted access to its technology.

Allied security agencies have also warned of Chinese access to AI research. Britain’s MI5 recently said some academics had unknowingly shared AI and cybersecurity work with an institute closely tied to Chinese intelligence.

Why This Matters

Experts tracking China-linked cyber activity say operatives are probing nearly every layer of the AI ecosystem — from chip design to model development and policy. Access to the private communications of AI policymakers and researchers could accelerate foreign understanding of U.S. strategy on export controls, military uses and governance, with potential implications for economic competitiveness and national security.

"Getting AI policy right is essential to our national security and economic competitiveness," said Lynne Parker, who confirmed colleagues alerted her after receiving suspicious emails impersonating her. "That includes protecting the people and institutions whose expertise helps inform those decisions."

Proofpoint said it notified affected organizations and industry partners as it investigated. CNN has requested comment from the Chinese Embassy in Washington; Beijing typically denies state-sponsored hacking allegations.

Help us improve.

Related Articles

Trending