Chinese hackers have launched a large-scale cyber operation targeting American artificial intelligence experts. The attackers used sophisticated social engineering methods, posing as employees of the leading AI company Anthropic as well as former high-ranking US administration officials. The main targets of the cybercriminals were analysts, lawyers, and scientists specializing in the military applications of AI and technology export controls.
Nature of Cyberattacks and Masking Techniques
According to security researchers from Proofpoint, the attacks targeted employees at think tanks, law firms, and leading US universities. Specifically, as part of one campaign, hackers impersonated Lynn Parker, a former high-ranking White House technology advisor under the Donald Trump and Joe Biden administrations. The attackers sent emails to experts inviting them to join a fictitious AI policy advisory committee, attaching malicious software to the documents.
In addition, in February 2026, a fake account of an Anthropic top manager was deployed. Under this cover, hackers approached employees at an American think tank requesting feedback regarding the "military integration of Claude," attempting to hijack victims' credentials during the correspondence and gain access to classified research and strategic developments.
Geopolitical Context and Beijing's Interests
Cybersecurity specialists emphasize that these operations are backed by groups supported by the Chinese government. The vector of the attacks fully aligns with Beijing's strategic interests amid intense technological competition between the US and China. The Donald Trump administration had previously repeatedly expressed concern over industrial espionage and the theft of trade secrets in artificial intelligence. Experts note that Chinese cyber operatives systematically target the entire AI ecosystem—from semiconductor manufacturers to academia.
Contradictory Data
At present, leading cybersecurity experts from Proofpoint state that no direct evidence of successful system breaches or critical data leaks has been found during these attacks. Nevertheless, analysts warn that the actual scope of malicious activity may be significantly broader, and state-backed hacker groups tend to continue campaigns until they achieve their goals. Official Beijing traditionally and categorically denies any involvement in state-sponsored cyber espionage and attacks on foreign infrastructure.
Implications for the AI Industry and Defense Measures
The threat of industrial espionage forces American tech companies, research institutions, and defense agencies to review digital hygiene standards. Studying the tactics used by hackers under the guise of Anthropic and government officials underscores the necessity of strict correspondence verification and the implementation of multi-factor authentication. Amid tightened export controls and tougher sanctions policies, the cyber standoff between major powers will only escalate, making artificial intelligence one of the primary arenas of geopolitical struggle.