Days After Trump Welcomes Xi, Months-Long China-Linked Campaign Targeting U.S. AI and Military Tech Exposed

Days After Trump Welcomes Xi, Months-Long China-Linked Campaign Targeting U.S. AI and Military Tech Exposed
Credit: Getty Images

A newly exposed cyber-espionage operation is drawing fresh attention to the national-security tensions surrounding America's technological relationship with China, only days after Trump gave Xi Jinping an elaborate state welcome in Washington. On October 1, cybersecurity firm Proofpoint revealed that a China-aligned threat actor it tracks as TA419 had repeatedly targeted people positioned close to U.S. artificial-intelligence policy, including experts involved with national-security questions, export controls and the military use of advanced AI. The disclosure followed Xi's September 23–25 state visit, during which Trump personally greeted the Chinese leader at Joint Base Andrews before hosting an official White House arrival ceremony and state dinner. Proofpoint's findings do not establish that Trump knew about this specific campaign when Xi arrived, but their publication days later creates a striking contrast between the diplomatic display and the continuing intelligence competition surrounding technologies that both countries increasingly view as strategically critical.

The campaign was not a single phishing attempt. Proofpoint says TA419 has been conducting espionage-focused activity since at least April 2025, with a series of operations in 2026 aimed specifically at gaining access to people with knowledge of American AI policy. In July, attackers impersonated prominent economists and AI policymakers while approaching experts working at U.S. think tanks, universities and legal organizations. Some targets received seemingly harmless invitations to participate in a fictitious «AI Policy Advisory Committee», while others were asked to contribute to what appeared to be a Senate Foreign Relations Committee report concerning AI export controls and supply chains. Once a target responded, the attackers could send a shortened link leading to a counterfeit OneDrive authentication page designed to capture cloud-account credentials. Proofpoint assessed that the operation likely served broader Chinese intelligence objectives by seeking insight into U.S. AI regulation, export restrictions and other strategic developments at the center of the intensifying technological competition between Washington and Beijing.

«The only control or ‘guardrails' that AI needs is a STRONG AND SMART (High IQ!) PRESIDENT, and the U.S.A. has that, in spades!»

-U.S. President, Donald Trump, on Truth Social

One of the most revealing episodes occurred months earlier, in February, when TA419 impersonated a senior employee at Anthropic, the American company behind Claude. The hackers contacted an AI policy analyst at a U.S. think tank using the subject line «Request for Feedback on Military Integration of Claude», deliberately placing the attempted intrusion inside an active debate over how advanced commercial AI systems could be used by the U.S. military. Proofpoint says the exchange ultimately led toward another credential-phishing chain intended to obtain access to the target's cloud account. The tactic illustrates why the operation matters beyond ordinary cybercrime: rather than indiscriminately attacking large numbers of users, TA419 selected people whose work could provide visibility into how Washington is thinking about AI, military applications, supply chains and technology restrictions involving China. Proofpoint described the campaign as espionage-motivated, while stopping short of claiming that the attempts successfully compromised the targeted organizations.

Getty Images

The timing of Proofpoint's disclosure is particularly striking because it arrived less than a week after Trump hosted Xi for a three-day state visit built around unusually warm diplomatic symbolism. Trump personally greeted the Chinese leader at Joint Base Andrews before a formal White House welcome, meetings and a state dinner, while publicly emphasizing the importance of improving relations between Washington and Beijing. Artificial intelligence was among the subjects discussed, and the two governments agreed to establish a U.S.-China dialogue covering the risks and benefits of what the administration now calls «Super Intelligence», along with a bilateral communication channel for serious AI-related incidents. Yet the summit produced no publicly announced agreement specifically addressing Chinese cyber-espionage against American AI policy circles. There is also no public evidence that Trump had been briefed on TA419 before receiving Xi, making the contrast one of timing rather than proof that the President knowingly overlooked this particular operation.

Getty Images

That contrast comes as Trump pursues an increasingly permissive approach to artificial-intelligence development at home. Shortly after Xi's visit, the administration formally directed the executive branch to replace the term «Artificial Intelligence» with «Super Intelligence», reflecting Trump's argument that the older name understates what the technology can accomplish. He has explained his dislike of the traditional terminology by saying: «The use of the word artificial makes intelligence fake, it makes it sound fake and it is not fake. It's actually amazing… The word super is the best word of all, and it's the simplest.» Trump has also resisted demands for extensive government restrictions, writing that «The only control or ‘guardrails' that AI needs is a STRONG AND SMART (High IQ!) PRESIDENT, and the U.S.A. has that, in spades!» His administration has instead emphasized voluntary industry safeguards, with Trump saying of major technology companies: «Well, I think I'm seeing tremendous self-policing, and they understand that they have to self-police.»

«The use of the word artificial makes intelligence fake, it makes it sound fake and it is not fake. It's actually amazing… The word super is the best word of all, and it's the simplest.»

-U.S. President, Donald Trump

Proofpoint's findings nevertheless illustrate that the competition surrounding advanced AI extends far beyond questions about how companies regulate their own models. TA419's targets included people working at think tanks, universities, defense contractors and law firms in the United States and Japan, and its 2026 campaigns sought access to individuals positioned to understand American thinking on AI policy, military applications, export controls and technology supply chains. Proofpoint assesses that the activity likely supports broader Chinese intelligence objectives, although its report does not claim that the phishing attempts successfully compromised the targeted organizations or prove that Beijing directly ordered each operation. That distinction is important, but so is the campaign's apparent objective: obtaining privileged visibility into how the United States is approaching technologies that could shape both economic competition and future warfare. Days after Washington and Beijing publicly promised a new dialogue on advanced AI, the disclosure offered a reminder that cooperation between the two governments continues alongside an intense and increasingly sophisticated intelligence contest over the same technology.

Getty Images

Created by humans, assisted by AI.