Security researchers at Proofpoint have linked a suspected Chinese espionage group, tracked as TA419, to phishing campaigns that impersonated AI policy figures, including a senior Anthropic employee and a former White House Office of Science and Technology Policy official. The bulk of the activity took place in July 2026, according to a Thursday report, and targeted AI policy experts at US universities, think tanks, and law firms.
Beginning July 8, the group sent emails spoofing Lynne Edwards Parker, former principal deputy director of the White House OSTP, and economist Heidi Crebo-Rediker. The lures invited recipients to join a fake AI policy advisory committee or contribute to a Senate foreign relations committee report on AI export controls and supply chains. Replies were met with shortened URLs that led to attacker-controlled domains, where a Cloudflare Turnstile check behind a fake OneDrive screen preceded an attacker-in-the-middle credential phishing page designed to steal Microsoft 365 login information.
Proofpoint also noted an earlier February campaign in which TA419 spoofed a senior Anthropic employee to phish an AI policy analyst at a US think tank, using the subject line 'Request for Feedback on Military Integration of Claude.' The group has impersonated other organizations as well, including the Heritage Foundation and a Japanese official's website. The researchers recommend phishing-resistant, origin-bound authentication such as passkeys for organizations in scope.