top of page

Hackers Borrow Trusted Names to Target America’s AI Experts

Writer: Bill Stortz
Bill Stortz
3 days ago
2 min read

An invitation to help shape artificial intelligence policy might seem like a professional opportunity. For some American researchers, it was instead the opening move in an alleged cyber-espionage campaign designed to gain access to their accounts.



Cybersecurity company Proofpoint reported October 1 that a China-aligned hacking group it tracks as TA419 impersonated prominent officials and researchers while approaching experts at think tanks, universities and law firms. The company assessed that the activity likely served Chinese intelligence interests in understanding American AI policy.


The approach exploited something familiar in professional life: an unexpected message from an influential person offering collaboration. A credible name and a relevant subject could make the outreach appear worth answering, particularly in a field where policy discussions frequently bring together government, academia and industry.


According to reporting by Nextgov/FCW, the impersonated figures included Lynne Parker, a former senior White House technology official, and Heidi Crebo-Rediker, the State Department’s former chief economist. Messages offered opportunities to advise on artificial intelligence or contribute to work concerning export controls and supply chains.


The July campaign included invitations to a fictitious advisory committee and requests connected to a purported Senate Foreign Relations Committee report. After recipients engaged, the attackers followed up with links intended to steal Microsoft account credentials. Nextgov reported that the findings did not establish whether accounts were successfully compromised or information was obtained.


One recipient recognized the deception. Alex Engler, a former White House official who leads the Penn Center on Media, Technology, and Democracy, told Reuters that an invitation apparently sent by Parker seemed unusual. After checking with others, he determined that the sender was an impostor.


Reuters reported that the recent targeting involved fewer than 10 people at a handful of organizations. Beijing has long denied conducting cyberespionage, and the Chinese Embassy did not immediately respond to Reuters’ request for comment.


The technical trap was more sophisticated than an ordinary fake login page. Proofpoint described a system that relayed genuine Microsoft authentication while capturing the resulting session information. That method could allow an attacker to benefit from a completed login even when the recipient supplied an additional authentication code.


Proofpoint recommended phishing-resistant authentication, including passkeys, and verifying unexpected professional outreach through a separate communication channel.


The campaign’s significance extends beyond the number of people approached. Policy researchers occupy a valuable position between emerging technology and the decisions governing its use. Their correspondence may illuminate developing arguments, professional relationships and proposals before those discussions become public.


That makes trust itself a potential security weakness. The apparent sender’s reputation can encourage a recipient to overlook warning signs that would be obvious in a message from a stranger.


The episode illustrates how competition over artificial intelligence reaches beyond laboratories and semiconductor factories. It also reaches the inboxes of people debating the technology’s future. In this case, the attempted entry point was an invitation, and the strongest defense was a recipient willing to question who had actually sent it.

Comments


Commenting on this post isn't available anymore. Contact the site owner for more info.
bottom of page