Summary
Anthropic reports that Claude AI was used in a political influence operation in Malaysia to create a fake news outlet and a network of 1,000 X accounts [1]. Proofpoint claims a China-aligned group, TA419, targeted US AI policy experts using phishing emails that impersonated officials and an Anthropic employee [2, 3, 4]. OpenAI says it disrupted a coordinated campaign to extract protected reasoning from its models, attributing a core cluster of the activity to individuals associated with Moonshot AI [5, 6, 7].
Main story: China-linked actors target AI policy experts and influence operations
Anthropic reported that Claude AI was used in a political influence operation in Malaysia [1]. The operation reportedly utilized a fake news outlet called "Malaysia Pulse," a network of approximately 1,000 X accounts, and fabricated documents [1]. The operation appeared designed to target voters in recent state elections by exploiting sensitive political and social fractures [1]. Anthropic stated in a September threat assessment that actors used Claude to build networks of fake social media profiles and news websites targeting audiences on six continents [1]. These actors reportedly included private firms selling influence, state media, and state-aligned propaganda institutions [1].
Proofpoint claims a China-aligned cyber espionage group, TA419, targeted US artificial intelligence policy experts through phishing emails [2, 3]. The group reportedly impersonated prominent officials, economists, and a senior employee from Anthropic [2, 3, 4]. One message reportedly asked an AI policy analyst for feedback on the military use of Claude models [3]. Proofpoint claims the group sought access to cloud accounts at law firms, universities, and think tanks [2]. The firm described the operation as an adversary-in-the-middle phishing attack using a modified version of an open-source tool called Frameless BitB [2]. Proofpoint reported that the group has targeted individuals connected to US and Japanese think tanks, defense contractors, and universities since at least April 2025 [2]. Proofpoint did not confirm any successful breaches or stolen credentials in this campaign [3].
Supplemental
OpenAI disrupts model distillation campaign
OpenAI says it disrupted a coordinated campaign designed to illicitly extract protected reasoning from its models [5, 8, 6]. The company characterized the activity as adversarial distillation, which involves the unauthorized use of one model's outputs to improve another model [8, 6]. OpenAI reported that the earliest activity occurred in the first week of July 2026 [5, 6]. The company attributed a core cluster of the activity to individuals associated with Moonshot AI, a Chinese AI company [5, 7]. OpenAI stated that operators manipulated model interactions to reproduce protected reasoning in forms visible to the requester [5, 8, 6]. The company reported observing a spike of 16,000 attempted requests from over 4,000 users on July 24 and 25, 2026 [8, 7].
Researchers identify SparLeak privacy risks
Researchers published a report describing SparLeak, a side-channel attack that targets sparse attention in large language models [9]. The researchers claim the attack exploits a GPU micro-architectural side channel termed Sparsity-Induced Memory Access (SIMA) [9]. This side channel arises from secret-dependent key-value cache access patterns [9]. The researchers claim SparLeak enables two types of privacy extractions: query attribute inference and autoregressive response reconstruction [9]. In evaluations, the researchers reported average attack success rates of 90.9% for attribute inference and 87.3% for response reconstruction [9].
References
- How AI could ’supercharge’ election risks across south-east Asia · www.theguardian.com · threat intel report · 2026-10-01 · RL-I-2026-0329
- AI policy circles targeted in China-linked phishing operation · cyberscoop · threat intel report · 2026-10-01 · RL-I-2026-0319
- Chinese hackers pose as US AI policy figures in campaign targeting AI experts · cryptobriefing.com · threat intel report · 2026-10-01 · RL-I-2026-0319
- China-linked hackers impersonated US AI insiders as global race heats up · www.cnn.com · threat intel report · 2026-10-01 · RL-I-2026-0319
- OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates · thehackernews · threat intel report · 2026-10-01 · RL-I-2026-0324
- OpenAI Disrupts Coordinated Model-Reasoning Extraction Campaign · www.unite.ai · threat intel report · 2026-09-30 · RL-I-2026-0324
- OpenAI reveals ‘novel’ encryption bypass used in distillation attack · cyberscoop · threat intel report · 2026-09-30 · RL-I-2026-0324
- Disrupting a coordinated model-distillation campaign · openai_blog · threat intel report · 2026-09-30 · RL-I-2026-0324
- SparLeak: Privacy Leakage from Sparse Attention in LLM Inference on Shared GPUs · arxiv_cs_cr · reproducible result · 2026-10-01 · RL-I-2026-0338