
Chinese hackers linked to the TA419 group are using tactics to disguise themselves as American artificial intelligence experts for phishing purposes. According to a report by Proofpoint, the attackers have been active since 2025 and are targeting organizations in the US and Japan. Among these organizations are think tanks, defense contractors, universities, and law firms. In a recent campaign, the hackers used the name Lynn Parker, who previously worked at the White House Office of Science and Technology Policy. In their emails, the criminals offered victims participation in joint AI initiatives, after which they redirected them to phishing sites to steal credentials. Reports indicate that the actions of the attackers affected about 10 employees from several IT organizations, indicating a targeted approach to victim selection.
One of the recipients, Alex Engler, a former White House staffer and head of a research center in Pennsylvania, told Reuters that he received an email supposedly from Parker inviting him to participate in a new AI project. However, suspecting fraud, Engler decided to discuss the email with other industry experts, which confirmed his suspicions: the sender was an imposter. Lynn Parker also confirmed that in early July, two people received suspicious messages in her name.
According to Proofpoint, the narrow selection of targets indicates the hackers' intelligence interest rather than just an attempt to steal technology. It is worth noting that Beijing has previously denied allegations of cyber espionage. In September, journalists learned about the investigation by Chinese authorities into the data leak of DeepSeek and Moonshot users in the US.




