Days after Trump welcomed Xi Jinping to Washington, a cybersecurity firm exposed a months-long China-linked espionage campaign seeking intelligence on U.S. AI and military technology. Proofpoint revealed that hackers tracked as TA419 repeatedly targeted experts close to American AI policy, export controls and defense applications, even impersonating an Anthropic executive, highlighting the intelligence competition continuing behind the diplomatic cooperation between Washington and Beijing.
China-Linked Espionage Campaign Exposed
Days after Trump gave Xi Jinping an elaborate state welcome in Washington, a newly exposed cyber-espionage campaign is drawing attention to the national-security tensions surrounding America’s technological relationship with China. On October 1, cybersecurity firm Proofpoint revealed that a China-aligned threat actor known as TA419 had repeatedly targeted people positioned close to sensitive areas of U.S. artificial-intelligence policy.
A Striking Post-Summit Revelation
The disclosure followed Xi’s September 23–25 state visit, during which Trump personally greeted the Chinese leader at Joint Base Andrews before hosting official ceremonies and a state dinner. Proofpoint’s findings do not establish that Trump knew about this specific campaign, but their publication days later created a striking contrast between diplomatic cooperation and the continuing intelligence competition surrounding advanced technology.
An Operation Dating Back to 2025
Proofpoint says TA419 has conducted espionage-focused activity since at least April 2025, with operations becoming increasingly focused on American AI policy during 2026. The hackers targeted experts whose work could provide insight into U.S. artificial-intelligence regulation, national-security priorities, export restrictions and technology supply chains as competition between Washington and Beijing intensified across strategically important technological sectors.
Elaborate Traps Target AI Experts
In July, attackers impersonated economists and AI policymakers while approaching experts at American think tanks, universities and legal organizations. Some targets were invited to join a fictitious «AI Policy Advisory Committee», while others received requests concerning a supposed Senate Foreign Relations Committee report about AI export controls, creating credible scenarios designed to encourage recipients to continue communicating with the attackers.
Fake Logins Designed to Steal Credentials
Once a target responded, TA419 could direct the victim toward a counterfeit OneDrive authentication page designed to capture cloud-account credentials. Proofpoint says the hackers also registered deceptive domains and used sophisticated phishing techniques to make their communications appear legitimate. The objective was not ordinary financial cybercrime, but access to information potentially valuable for intelligence purposes.
Anthropic Executive Impersonated
One particularly notable attempt occurred in February, when TA419 impersonated a senior employee at Anthropic, the American company behind Claude. Hackers approached an AI policy analyst at a U.S. think tank with the subject line «Request for Feedback on Military Integration of Claude», deliberately exploiting an active debate about incorporating advanced commercial artificial intelligence into military operations.
Military AI Becomes an Intelligence Target
The Anthropic impersonation eventually led toward another credential-phishing attempt. Proofpoint believes TA419 selected individuals capable of providing visibility into how Washington approaches AI, military applications, export controls and technology restrictions involving China. However, the cybersecurity firm did not report evidence that the targeted organizations were successfully compromised, an important distinction when assessing the campaign’s ultimate impact.
Trump Gives Xi a Warm Welcome
The revelation came less than a week after Trump hosted Xi for a three-day state visit emphasizing warmer relations between Washington and Beijing. Artificial intelligence was among the issues discussed, with both governments agreeing to establish dialogue concerning advanced AI and a communication channel for serious AI-related incidents, even as strategic technological competition between the countries continued.
Trump Pushes «Super Intelligence»
Trump has simultaneously promoted a different approach to AI at home, including replacing the term «Artificial Intelligence» with «Super Intelligence». Explaining his preference, he said: «The use of the word artificial makes intelligence fake, it makes it sound fake and it is not fake. It’s actually amazing… The word super is the best word of all, and it’s the simplest.»
Trump Rejects Extensive AI Guardrails
Trump has also resisted calls for extensive government restrictions on AI, writing: «The only control or ‘guardrails’ that AI needs is a STRONG AND SMART (High IQ!) PRESIDENT, and the U.S.A. has that, in spades!» His administration has instead emphasized voluntary industry safeguards, while the newly exposed espionage campaign highlights a separate security challenge involving foreign efforts to obtain strategic information.
Cooperation Alongside Intelligence Competition
Proofpoint assesses that TA419’s activity likely supports broader Chinese intelligence objectives, although it does not claim Beijing directly ordered every operation. Days after Washington and Beijing promoted new cooperation on advanced AI, the disclosure illustrated a parallel reality: both countries remain locked in an increasingly sophisticated intelligence and technological competition over AI systems that could shape economic power and future warfare.