Unbiased headlines. Facts, not spin.
Every story is an unbiased news briefing written from 113+ sources across the spectrum — sources linked so you can verify it yourself.
Chinese Hackers Posed as Ex-White House Official and Anthropic Staffer to Target US AI Policy Experts, Proofpoint Says

A Chinese government-aligned hacking group spent more than a year impersonating American AI policy experts, including a former White House official and an Anthropic employee, to steal login credentials from people who shape US artificial intelligence policy, according to a report published Thursday, October 1, by cybersecurity firm Proofpoint.
Proofpoint tracks the group as TA419 and says it has been running credential-phishing campaigns against staff at US and Japanese think tanks, defense contractors, universities and law firms since at least April 2025. Thursday's report was the first public disclosure of the group's activity, according to Infosecurity Magazine.
How the scam worked
Starting July 8, the hackers sent emails under the name of Lynne Parker, who served as principal deputy director of the White House Office of Science and Technology Policy under both the Trump and Biden administrations, Infosecurity Magazine reported. They later impersonated economist and foreign policy expert Heidi Crebo-Rediker. In February, the same group had posed as a senior Anthropic employee to contact a think tank analyst working on AI policy, according to CNN.
The opening pitch was mundane: an invitation to join a fictitious "AI Policy Advisory Committee" or help with a Senate Committee on Foreign Relations report on AI export controls. Anyone who responded was sent a shortened link that redirected through several hops to a fake Microsoft OneDrive login page, Infosecurity Magazine reported.
That page was built using an open-source tool called Frameless BitB to draw a convincing fake browser window, and it functioned as an adversary-in-the-middle reverse proxy. Because it forwarded victims' real Microsoft 365 credentials to Microsoft in real time, passwords, multifactor codes and conditional-access checks all passed, letting TA419 walk away with live session cookies instead of just a password, according to Infosecurity Magazine. The tool automatically checked "Keep me signed in" to extend how long the stolen session stayed valid.
Who got targeted
Proofpoint said the targeting involved fewer than 10 individuals across a handful of organizations. The firm declined to name victims but said they included "experts working on AI regulation, export controls and national AI strategy."
Reuters independently identified one target: Alex Engler, who now heads the Penn Center on Media, Technology, and Democracy. Engler told Reuters he received an email appearing to come from Parker inviting him "to join a new AI policy project," but the message "felt slightly, nebulously off." After checking with colleagues, he realized it was an impostor.
Parker told Reuters that Engler was one of two people she knew of who received messages impersonating her in early July. "The United States and China are in a competition around AI," she said. "Trying to get people in the AI policy space to reveal information about their AI policy plans, if that indeed was what the objective was, it's not surprising."
Proofpoint attributed the campaign to a Chinese group based on the malware used, the internet infrastructure involved, and targeting patterns it said align with Chinese intelligence priorities. Proofpoint researcher Mark Kelly told CNN the firm is "confident" the group is "a Chinese government-aligned threat actor based on targeting consistently in line with Chinese government interests, observed infrastructure and technical artifacts, and corroboration from industry partners."
Proofpoint said it found no evidence of successful breaches at the targeted organizations, but cautioned it may not have full visibility and that Beijing-linked groups typically keep trying until they get in.
Attribution and context
The Chinese Embassy in Washington did not respond to requests for comment from Reuters or CNN. Beijing has consistently denied running cyberespionage operations, and no US charges or indictments have been announced over this specific campaign. The attribution rests on Proofpoint's technical analysis, not a government finding.
Attribution in cyberespionage cases is notoriously hard to verify independently. Proofpoint is a private firm with a commercial interest in flagging threats, and its conclusions, while detailed, have not been confirmed by a US government agency in this instance.
The campaign comes amid a broader US-China standoff over AI. President Donald Trump met with Chinese leader Xi Jinping last week to discuss AI, but the meeting produced no substantive accord, according to CNN. Trump has resisted calls to impose guardrails on advanced AI models, wary of ceding ground to China in the race for AI dominance.
Last month, the Trump administration accused Chinese AI firms of "industrial-scale" theft of American trade secrets, an allegation China has denied, CNN reported. Britain's MI5 said this week that some British academics had contributed AI and cybersecurity research to a Chinese institute with ties to Chinese intelligence, in some cases without realizing the connection. And a House committee has said Chinese state-linked actors used similar impersonation tactics in 2025 against Congressman John Moolenaar, according to Infosecurity Magazine.
Proofpoint is advising targeted organizations to move to phishing-resistant sign-in methods like passkeys and to verify unsolicited outreach through a separate channel before responding. Whether TA419 ever got inside a target's inbox remains unconfirmed. Proofpoint says it's still watching, and expects the group to keep impersonating real experts as the AI policy fight between Washington and Beijing continues.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.