Skip to content

Security2 publishers2 min readPublished

TA419 courts AI policy experts before phishing their cloud accounts

Proofpoint says China-aligned TA419 has posed as a former White House official and an Anthropic employee to phish AI policy experts since at least April 2025. The first approach asks for nothing; the credential-stealing link follows only after a target replies.

The Watch · Security desk

What happened

  • From July 8 the emails carried the names of Lynne Parker, a former White House science-office deputy director, and economist Heidi Crebo-Rediker, with invitations to a made-up AI Policy Advisory Committee or an export-controls report.
  • A February campaign used the identity of a senior Anthropic employee to ask a US think-tank analyst for feedback on the military's use of Anthropic's Claude models.
  • The spoofed Microsoft OneDrive sign-in page is an adversary-in-the-middle proxy built from Frameless BitB, an open-source kit that draws a fake browser window inside a webpage.
  • Because the proxy forwards each login to Microsoft in real time, the password, MFA code and conditional-access checks all pass, and TA419 walks away with the session cookies.
  • The group also registered web domains resembling the Heritage Foundation, the World Economic Forum and the Japan-Taiwan Exchange Association.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure The target set is the AI policy community itself: think tank, university and law firm staff whose cloud accounts hold export-control and national-security work.
  • constraint A password plus an MFA prompt no longer protects these accounts against the proxy; Proofpoint says defenders need phishing-resistant sign-in such as passkeys.
  • precedent Proofpoint expects TA419 to keep impersonating real experts, so a credible invitation from a known name is a standing attack vector in this field.

The kit does more than copy a login screen. Proofpoint says TA419 added a module that tracks where each victim sits in the login flow, ticks "Keep me signed in" automatically so the stolen session lasts longer, and enters one-time codes the moment Microsoft accepts them [12]. The shortened link bounces through several redirects before it reaches the fake OneDrive page [9].

October 1 was the first public account of TA419 [4]. The report does not identify a victim or say whether any account was taken [13]. It does not directly tie the group to the Chinese government, and China has repeatedly denied conducting cyber espionage while accusing the United States of the same [15]. Proofpoint says the campaigns likely feed Chinese intelligence collection on how US AI policy and export controls are developing [16], and it describes the AI targeting as an extension of the group's existing work on defense, national security and foreign policy [20]. The White House and several AI companies have separately accused China of distilling US models to power Chinese open-weight systems [21].

The tactic has a recent precedent. A House committee said Chinese state-linked actors used the same approach in 2025, impersonating Congressman John Moolenaar [17].

Proofpoint's guidance to the people being targeted is to treat the friendly first email as the attack. "Individual targets in scope of TA419 activity should treat unsolicited subject-matter outreach as a plausible pretext stage," the company wrote, "and seek to verify the legitimacy of such unexpected communications via another independent medium." [19]

What to watch

  • Whether Proofpoint or others attribute TA419 to a specific Chinese agency, which the current report does not do.
  • Whether any named victim or confirmed account takeover surfaces from this campaign.
  • Whether the group rotates to new impersonated names or new lures beyond the advisory-committee and export-controls pretexts.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories