China-linked hackers, attributed to the TA419 group, impersonate AI experts to target US policy-focused individuals, according to multiple reports. The campaign uses deceptive personas to phish for access to Microsoft 365 accounts and to obtain information related to AI policy work.

The outlets describe tactics in which attackers pose as real figures, including people connected to US government or AI policy circles. Al Jazeera and Infosecurity Magazine both report that the impersonation is designed to appear credible to the intended victims, while NDTV says the phishing emails specifically aim to steal login credentials and related information about AI policy and strategy.

All sources cite cyber-security analysis, with NDTV pointing to Proofpoint’s assessment. NDTV adds that the targets are limited in number—fewer than 10 people—suggesting a narrow, highly selective approach rather than broad-scale phishing. While the reports agree on the overall method and goal, they differ mainly in how they describe the impersonated identities and the level of detail about the target set.