Morganable Technology | Cybersecurity
Hackers impersonate AI experts in targeted phishing campaign aimed at stealing email passwords
Lagos —
Cybersecurity experts have uncovered a targeted hacking campaign in which attackers are impersonating prominent artificial intelligence (AI) experts to steal the email credentials of people working in the field.
Reuters reported on Thursday that Proofpoint has been tracking the group, which it calls TA419, since at least 2025. The group has targeted people connected to think tanks, universities, defence contractors and law firms in the United States and Japan.
The latest campaign uses a familiar cybercrime method, but with a more convincing approach.
Instead of sending an obvious fake message, the attackers pretend to be people known within the AI community. They then use the fake identity to make their emails appear trustworthy.
According to Proofpoint, some of the emails claimed to be from experts in AI or government policy. The messages often proposed collaboration on AI projects or invited the recipient to take part in a new initiative.
The goal was to get the recipient to click a link.
Once clicked, the link directed the target to a fake website designed to steal passwords and other login information.
One of the people targeted was Alex Engler, a former White House official who now heads the Penn Center on Media, Technology, and Democracy.
Engler told Reuters that he received an email that appeared to come from Lynne Parker, a former senior official at the White House Office of Science and Technology Policy.
The message invited him to join what appeared to be a new AI policy project.
However, Engler noticed that something did not seem right. He checked with other people in the field and discovered that the message was not genuine.
Parker told Reuters that two people received suspicious messages pretending to come from her in early July.
The incident shows how cybercriminals are changing their methods as technology professionals become more familiar with traditional phishing emails.
Phishing is a cyberattack in which criminals use fake emails, websites or messages to trick people into giving away sensitive information.
This may include passwords, banking details or other account information.
In this case, the attackers added another layer to the deception by using familiar names and professional relationships.
That approach can make an attack harder to detect.
A recipient may ignore an email from an unknown sender. However, a message that appears to come from a respected researcher, government official or industry colleague may receive more attention.
Proofpoint said the campaign involved fewer than 10 people across a small number of organisations.
The cybersecurity company believes the activity may be linked to intelligence gathering rather than ordinary financial cybercrime. It based its assessment on the malware used, the infrastructure behind the attacks and the types of people targeted.
The targets included people working on AI regulation, export controls and national AI strategies.
This is important because AI has become a major area of competition between countries and technology companies.
Information about AI policies, regulations and technology development can have economic and strategic value.
However, Proofpoint’s assessment is not the same as a public confirmation by the Chinese government.
The Chinese Embassy in Washington did not immediately respond to Reuters’ request for comment. Beijing has repeatedly denied accusations that it carries out cyber-espionage operations.
For businesses and organisations, the incident is another reminder that cybersecurity is not only about protecting computers.
People remain a major part of the security chain.
Even experienced technology professionals can be targeted through carefully prepared messages. Attackers can research their victims, study their professional interests and create messages that appear relevant.
As a result, organisations need to pay attention to the small details in emails.
Employees should check the sender’s address before clicking links. They should also be cautious when a message suddenly asks them to log in, download a file or provide sensitive information.
When an email involves an important project or an unusual request, the recipient can confirm it through another communication channel.
For example, instead of replying directly to the suspicious email, the person can contact the supposed sender through a known phone number or existing work account.
Technology companies and research institutions may also need stronger protection around staff accounts.
Multi-factor authentication can make it harder for attackers to access an account even when a password has been stolen.
Regular cybersecurity training can also help employees recognise social engineering attacks.
Social engineering involves manipulating people into taking an action that benefits the attacker. It can be especially effective when the message is built around a person’s work, interests or professional relationships.
The latest campaign highlights a wider problem for the growing AI industry.
As AI becomes more important to governments, businesses and researchers, information connected to the sector is becoming a valuable target.
Hackers are therefore finding new ways to get close to the people who hold that information.
The attack also shows why trust must be balanced with caution.
An email may look professional. It may mention a genuine project. It may even appear to come from someone the recipient knows.
That does not automatically make it safe.
For AI researchers, technology companies and organisations handling sensitive information, verifying unexpected requests remains one of the simplest ways to reduce the risk of a successful attack.
Organisations can also limit the damage from stolen credentials by using strong access controls. Staff should only have access to the information needed for their roles.
This can prevent a compromised account from giving an attacker access to an entire organisation.
The incident is also a reminder that cyberattacks are becoming more personalised.
Criminals no longer have to send thousands of random messages and hope that someone responds. A carefully researched message sent to the right person can potentially provide access to valuable information.
As AI continues to influence government policy, business decisions and research, experts in the sector are likely to remain attractive targets.
For organisations, the lesson is straightforward.
Cybersecurity must combine technology with human awareness.
Strong passwords, multi-factor authentication and security software remain important. But employees must also know when to slow down, verify a request and question an unusual message.
The growing use of AI will continue to create new opportunities. At the same time, it will create new targets for cybercriminals.
For organisations working in the sector, protecting AI information means protecting the people who have access to it.












