Proofpoint Identifies China-Aligned Phishing Campaigns Targeting U.S. AI Policy Experts
The attackers impersonated policy figures and an Anthropic employee, then relayed real Microsoft sign-ins to steal account access. Proofpoint assesses the activity as intelligence gathering.
Proofpoint says China-aligned group TA419 used staged professional outreach to steal Microsoft 365 and Entra ID sessions from U.S. AI-policy experts, extending its established espionage focus rather than signaling a new mission. July 2026 approaches impersonated Lynne Edwards Parker and Heidi Crebo-Rediker, while a February message posed as a senior Anthropic employee; attackers waited for replies before sending links through controlled redirects to a fake OneDrive sign-in. Proofpoint disclosed no compromise count, leaving the campaign’s reach unknown; origin-bound passkeys and independent verification are practical defenses.
01
The phishing proxy relayed sign-ins to Microsoft while capturing passwords, multifactor codes and session cookies.
02
TA419 used a customized Frameless BitB fake-browser window and automated code submission to extend stolen sessions.
03
Proofpoint assesses the campaigns likely supported Chinese intelligence efforts to understand U.S. AI policy and regulation.
An invitation to help shape AI policy became bait for account theft. In an October 1 disclosure, Proofpoint attributed phishing campaigns against U.S. AI policy experts to TA419, a China-aligned espionage group. Its targets worked at think tanks, universities and law firms.
The AI-themed approach appeared months before the July campaigns. In February 2026, TA419 impersonated a senior Anthropic employee to contact an AI policy analyst at a U.S. think tank. The subject was “Request for Feedback on Military Integration of Claude,” and the message led to a similar credential-theft chain.
Beginning July 8, the group impersonated Lynne Edwards Parker, a former White House science-policy official, and economist Heidi Crebo-Rediker. The opening emails invited recipients to join a fictitious “AI Policy Advisory Committee” or contribute to a Senate Foreign Relations Committee report on AI export controls and supply chains.
The malicious link came only after a reply. TA419 then sent a shortened URL, presented as additional information, that passed through attacker-controlled sites to a fake OneDrive page. Both July campaigns shared the same redirect and phishing domains, driftshare[.]co and globalfileshareplatform[.]com.
The trap targeted Microsoft 365 and Entra ID, Microsoft's identity service. It used an “adversary-in-the-middle” proxy: an attacker-controlled intermediary relaying the target's sign-in to genuine Microsoft infrastructure. A customized open-source tool, Frameless BitB, supplied a fake browser window inside the page.
That relay allowed the password, multifactor authentication code and conditional access checks to succeed while the attacker captured session cookies—the data maintaining a signed-in session. TA419 also added automation that tracked progress, submitted validated one-time codes and accepted “Keep me signed in” to extend the stolen session.
Proofpoint assesses that the campaigns likely serve Chinese intelligence efforts to understand U.S. AI policy and regulation. It describes the targeting as an extension of TA419's existing interests, not a new mission. The firm has tracked the group attacking U.S.- and Japan-linked organizations since at least April 2025.
Proofpoint does not disclose how many targeted accounts were compromised. It expects TA419 to keep approaching policy experts and impersonating real specialists, leaving recipients to distinguish legitimate professional outreach from a staged relationship intended to steal access.
Its defensive recommendations address both stages: organizations should consider phishing-resistant authentication such as passkeys, bound to the legitimate site's origin. Individuals should verify unexpected subject-matter outreach through another independent channel, rather than treating a familiar policy topic or prominent sender's name as sufficient reassurance.
Sources
proofpoint.comHallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles | Proofpoint US
Reader comments
Newest comments first. Replies stay oldest first.