Phantom in the Inbox: How Suspected Chinese Operatives Hunt America’s AI Secrets

Chinese hackers impersonated Anthropic employee in a cyber-espionage campaign targeting US AI policy experts, with a laptop, Capitol building, Chinese flag, servers and AI imagery symbolising the theft of sensitive artificial intelligence secrets.

The email arrived on 26 February and looked entirely reasonable. A senior person at Anthropic wanted feedback on military uses of Claude, and the analyst who received it worked on exactly that question. Nobody at Anthropic had written a word of it. Investigators now believe Chinese hackers impersonated Anthropic employee.

A Borrowed Identity

On 1 October 2026, the cybersecurity firm Proofpoint published a report attributing the campaign to a China-aligned, espionage-motivated group it tracks as TA419.

The February message carried a subject line about the military integration of Claude and landed in the inbox of an AI policy analyst at an American think tank. The timing mattered: US military officials were then pressing Anthropic over the guardrails on its models. Proofpoint declined to name the impersonated employee and would not say whether anyone surrendered a password.

The Trap Behind the Handshake

The group widened its net in the summer. From 8 July, it impersonated Lynne Parker, a former principal deputy director of the White House Office of Science and Technology Policy, and then Heidi Crebo-Rediker, a former chief economist at the State Department.

The emails flattered their targets. One invited recipients to join an “AI Policy Advisory Committee” that does not exist. Another sought contributions to a supposed Senate report on AI export controls and supply chains. Crucially, the first message asked for nothing. It simply opened a conversation and built rapport, and only after a reply did the group send a shortened link.

That link bounced victims through several sites before reaching a counterfeit Microsoft OneDrive page. The attackers used a modified version of an open-source tool called Frameless BitB, which paints a fake browser window inside a real webpage so the sign-in prompt looks genuine.

The operation then ran as an adversary-in-the-middle attack. Victims entered their passwords and completed multi-factor prompts against real Microsoft infrastructure, while the attackers harvested the credentials and the live session. TA419 also registered lookalike domains echoing the Heritage Foundation, the World Economic Forum and the Japan-Taiwan Exchange Association.

Why Spies Court the Policy Crowd

Engineers hold the model weights. Policy experts hold something arguably more useful: the rulebook and the arguments behind it. They draft licensing thresholds, advise senators on export controls and sit on calls where officials weigh military adoption of frontier models. Their inboxes carry candid assessments that never reach a press release.

Proofpoint reads the targeting that way. The group appears to want insight into how Washington shapes AI policy rather than the technology itself, and it has been active since at least April 2025. Parker, whose identity was borrowed, has argued publicly that sound AI policy underpins both national security and economic competitiveness.

Stealing the Blueprints

Phishing is only the newest tactic. The oldest one still works: hire the engineer, or turn him. In January 2026, a San Francisco jury convicted Linwei Ding on fourteen counts, seven of economic espionage and seven of trade secret theft.

The evidence told a patient story. Ding joined Google in 2019 and worked on supercomputing data centres. Between May 2022 and April 2023, he copied more than two thousand pages of confidential material into a personal cloud account. The documents described Google’s TPU and GPU systems, its cluster software and its custom SmartNIC hardware, which together amount to a recipe for training large models at scale.

Meanwhile, Ding founded a technology company in Shanghai and applied to a Beijing-backed talent programme that recruits researchers working abroad. He downloaded the files to his own computer a fortnight before resigning.

Buying the Hardware

Washington bars the export of advanced AI chips to China without a licence, so smugglers route them elsewhere first. In March 2026, federal prosecutors charged three men, including a Super Micro Computer co-founder. The indictment describes billions of dollars in Nvidia-powered servers diverted to Chinese buyers, with middlemen allegedly producing fake paperwork and repackaging the machines in transit.

Taiwan followed in August, when prosecutors in Keelung indicted nine people, among them employees of Nvidia’s and Supermicro’s Taiwanese units. They allegedly moved 74 servers carrying high-end B300 chips through Japan and Indonesia. The pattern continues: on 1 October 2026, agents in Los Angeles arrested a California businessman over an alleged $300 million scheme. Prosecutors say he routed export-controlled servers through Malaysia and Singapore without ever seeking a licence.

Copying the Minds

A third route needs neither a spy nor a shipping container, only an account and patience. Engineers call it distillation: an operator floods a rival model with millions of queries, harvests the answers and trains a cheaper imitator on them.

Anthropic raised the alarm in February 2026, telling lawmakers that DeepSeek, Moonshot AI and MiniMax had run extraction campaigns against Claude, involving roughly 24,000 fraudulent accounts and more than 16 million exchanges. The White House responded on 23 April with a memorandum on adversarial distillation, in which the Office of Science and Technology Policy accused foreign entities, chiefly in China, of industrial-scale copying and pledged intelligence sharing with American AI firms.

Then came the largest case yet. In a letter dated 10 June, Anthropic told the Senate Banking Committee that operators tied to Alibaba’s Qwen lab had gone further, with, according to reports, about 25,000 fake accounts and 28.8 million exchanges in 44 days.

Recruiting the Researchers

Britain learned its own version of this lesson one day before the Proofpoint report landed. On 30 September, MI5 issued a rare public espionage alert naming the China General Technology Research Institute and describing very strong ties to the Ministry of State Security. More than 100 UK-based academics had contributed to projects the institute funded, in artificial intelligence, cybersecurity, covert communications and steganography, four fields that map neatly onto intelligence tradecraft.

Many scholars had no idea who ultimately paid. Security minister Dan Jarvis wrote to every university head and told academics to end the arrangements, saying Chinese intelligence had covertly exploited British expertise.

Turning the Tools Around

The boldest move inverts the whole problem: why steal an American model when you can simply operate one? In November 2025, Anthropic disclosed that it had disrupted a campaign it attributes with high confidence to a Chinese state-sponsored group. The attackers posed as a legitimate security firm and broke their work into innocuous-looking tasks.

Claude Code then did most of the rest. It scanned infrastructure, wrote exploit code, harvested credentials and prepared data for extraction. Anthropic estimates the AI executed 80 to 90 per cent of the operation, with human operators intervening at only a handful of decision points. The campaign targeted roughly thirty organisations and succeeded against a few.

Denials, Defences and the Thinnest of Walls

Beijing rejects all of it. Chinese officials routinely deny state hacking and accuse Washington of the same conduct, and the embassy in Washington says China’s AI progress reflects domestic research and fair international cooperation. Proofpoint stops short of naming the Chinese government, calling TA419 China-aligned and expecting it to keep working.

The defensive advice sounds almost mundane. Proofpoint urges organisations to adopt phishing-resistant, origin-bound authentication such as passkeys, and tells experts to treat unexpected professional outreach as a possible pretext, verifying the sender through a separate channel before clicking anything.

That guidance exposes an uncomfortable truth. Billions of dollars now guard the compute, the weights and the chips, yet the attackers walked past all of it and knocked on a researcher’s inbox instead. None of the campaigns described here required a breakthrough. They required a familiar name, a plausible subject line and a busy reader. The hardest technology to export-control remains ordinary human trust.

Somewhere today, another polite invitation lands. It flatters its reader, mentions a committee and asks for nothing at all. The asking comes later.

Exit mobile version