China-aligned TA419 impersonates White House and Anthropic figures to phish AI policy experts
Proofpoint says China-aligned group TA419 posed as prominent US AI policy figures to steal credentials and session data from think tank and university experts.
At a glance
- Proofpoint attributes the campaign to TA419, a China-aligned espionage group tracked since at least April 2025
- Lures impersonated former White House official Lynne Parker, economist Heidi Crebo-Rediker and a senior Anthropic employee
- Fake OneDrive login windows built with a modified Frameless BitB tool were used to capture credentials and session data, bypassing MFA
- Proofpoint did not identify specific victims or confirm compromised accounts
A China-aligned cyber espionage group tracked as TA419 has been targeting US experts working on artificial intelligence policy with phishing emails that impersonate prominent policy figures, according to research published by Proofpoint on October 1. The campaign aimed at specialists at think tanks, universities and law firms, and was designed to steal not only passwords but the session data that lets attackers bypass multifactor authentication. Proofpoint said the activity likely supports wider Chinese intelligence objectives around US AI policy.
What happened
According to CyberScoop, TA419 began the campaign in July by impersonating Lynne Parker, a former principal deputy director of the White House Office of Science and Technology Policy, and economist and foreign policy expert Heidi Crebo-Rediker. The emails invited recipients to join a supposed "AI Policy Advisory Committee" or to contribute to a report on AI export controls and supply chains.
In a separate operation in February, the group impersonated a senior Anthropic employee and asked an AI policy analyst at a US think tank for feedback on military applications of the company's AI models, CyberScoop reported. There is no indication that Anthropic's own systems were affected. Proofpoint said TA419 has targeted people connected to US and Japanese think tanks, defense contractors, universities and law firms since April 2025.
Technical details
According to Proofpoint's findings, as reported by CyberScoop and Help Net Security, the first emails contained no links and simply tried to start a conversation and build trust. Once a target replied, the group sent a shortened URL that redirected through several websites before landing on a fake Microsoft OneDrive sign-in page.
Proofpoint described the technique as an adversary-in-the-middle phishing attack. The group used a modified version of the open-source tool Frameless BitB to display a fake browser window mimicking a Chrome login, while Help Net Security reports that Cloudflare Turnstile checks were used to filter visitors. Victims could enter their password and complete MFA while the attackers captured the resulting session information. TA419 also registered domains resembling the Heritage Foundation, the World Economic Forum and the Japan-Taiwan Exchange Association, according to CyberScoop.
Who is affected
The campaign targets individuals rather than a specific product. Proofpoint did not identify specific victims or confirm that any accounts were compromised. The Record, reporting on the same day, noted separate research from Cisco Talos and Symantec on China-linked campaigns targeting governments and organizations across Asia, underscoring a broader focus on policy and technology targets.
What to do
Organizations working on AI, technology or national security policy should treat unsolicited invitations to committees, reports or advisory roles with caution, especially when a follow-up message contains a shortened link. Phishing-resistant MFA such as FIDO2 security keys or passkeys is significantly more effective than one-time codes against session-stealing attacks. Security teams should also watch for unusual sign-ins following OneDrive or Microsoft 365 logins and revoke active sessions for any account suspected of exposure.
Sources
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



