Proofpoint said a group it calls TA419 has been impersonating US AI experts, including a former government official, in an effort to steal emails from people at think tanks, universities and other organisations. Reuters reported that Proofpoint has observed the group trying to steal passwords from people at US and Japanese think tanks, defence contractors, universities and law firms since as far back as 2025.
The recent campaign used emails that appeared to come from experts in AI or statecraft. According to Proofpoint, the messages typically proposed AI-related collaborations or initiatives before sending recipients toward websites designed to steal passwords. Proofpoint said the activity was linked to a Chinese group based on malware, internet infrastructure and the targets observed.
The story matters for students, researchers and professionals because AI-related work can itself become the theme used in targeted phishing attempts. Familiarity with the sender or an apparently relevant research proposal does not by itself establish that an email is genuine.
Reuters independently identified one target as Alex Engler, a former White House official who now heads the Penn Center on Media, Technology, and Democracy. Proofpoint said targets included experts working on AI regulation, export controls and national AI strategy.