A suspected Chinese espionage operation impersonated prominent AI policy figures, including a senior Anthropic executive and a former White House official, to steal login credentials from American AI policy specialists, according to a Thursday report from Proofpoint. The security firm attributed the phishing campaigns to TA419, a China-aligned threat group it tracks, with most attacks concentrated in July 2026. The espionage effort targeted AI policy experts at US universities, think tanks, and law firms through fake invitations to advisory committees and research projects.
Starting July 8, TA419 sent phishing emails spoofing Lynne Edwards Parker, the former principal deputy director of the White House Office of Science and Technology Policy, and Heidi Crebo-Rediker, a well-known economist and foreign policy specialist, to American AI policy experts. The messages invited recipients to join a fabricated AI policy advisory committee or contribute to a Senate foreign relations committee report on AI export controls and supply chains. When targets responded, the attackers sent shortened URLs that appeared to share additional information but instead directed victims to an attacker-controlled domain. The malicious page performed a Cloudflare Turnstile check behind a fake OneDrive loading screen before redirecting to an attacker-in-the-middle credential phishing page that captured cloud account login details. In February, the same group impersonated a senior Anthropic employee to phish an AI policy analyst at a US think tank using the subject line "Request for Feedback on Military Integration of Claude."
"In July 2026, TA419 impersonated multiple individuals, including a former member of the White House Office of Science and Technology Policy leadership team, in credential phishing campaigns targeting AI policy experts in the US," wrote Proofpoint threat-intelligence analyst Mark Kelly in the report. The July 2026 campaigns used driftshare[.]co as the first-stage domain and globalfileshareplatform[.]com as the second-stage domain. The phishing infrastructure targets Microsoft 365/Entra ID through the first-party OfficeHome application and is built on open-source Frameless BitB, which contains a Browser-in-the-Browser overlay and an Evilginx phishlet to intercept usernames, passwords, and session cookies.
TA419 typically relies on Cloudflare's content delivery network to conceal the backend hosting IP addresses for its domains, and its credential phishing domains are usually themed around file-sharing sites and cloud services such as msfile[.]online and onecloudfilesync[.]com, according to the report. The group also impersonates specific organizations, including the Japan-Taiwan Exchange Association, The Heritage Foundation, and Japanese Minister of Defense Shinjirō Koizumi's official website. In total, the crew operates dozens of phishing and spoofed-sender domains along with fake email addresses. TA419 and other Beijing-aligned groups will likely continue targeting AI and other policy experts working on technologies of interest to the Chinese government, the threat hunters warn. Proofpoint recommends that organizations within TA419's scope consider phishing-resistant, origin-bound authentication such as passkeys. The sophistication of social engineering techniques aimed at AI policy circles suggests organizations may need to rethink how they verify the authenticity of professional invitations. Trust networks built on familiar names and institutional affiliations become vulnerabilities when adversaries can convincingly replicate both.

