Skip to content
EspionageOngoing

TA419 China-aligned phishing campaign impersonates Anthropic and US officials to target AI policy experts

Proofpoint disclosed that China-aligned actor TA419 impersonated a senior Anthropic employee and former US officials in credential-phishing campaigns aimed at AI policy experts at American think tanks, in an apparent effort to collect intelligence on US artificial-intelligence policy.

Victim
U.S. AI policy experts and think tanks

On 2 October 2026, threat-intelligence firm Proofpoint disclosed a China-aligned espionage campaign, tracked as TA419, that impersonated prominent figures in US artificial-intelligence policy to phish experts at American think tanks and research organisations. In a report authored by analyst Mark Kelly, Proofpoint said the activity likely supports broader Chinese intelligence objectives as governments race to shape AI policy and military applications.

The operators impersonated a senior Anthropic employee in February 2026 to approach an AI policy analyst, using an email subject referencing the debate over military integration of Anthropic's Claude models. Beginning 8 July 2026, TA419 expanded the effort by posing as former US officials โ€” Lynne Edwards Parker, a former Principal Deputy Director of the White House Office of Science and Technology Policy, and economist and foreign-policy expert Heidi Crebo-Rediker.

Technique

The campaign relied on social-engineering lures rather than malware. Initial emails carried no malicious links and instead invited targets to join fictitious bodies such as an "AI Policy Advisory Committee" or to contribute to policy reports. Once a target engaged, follow-up messages used shortened URLs leading to fake OneDrive credential-phishing pages. The attackers deployed Frameless BitB, an open-source browser-in-the-browser tool that simulates a Chrome login window, to capture credentials, multi-factor authentication codes and session cookies. TA419's infrastructure used Cloudflare's CDN and domains registered through NameSilo.

Significance

Proofpoint found no evidence of successful breaches of the targeted organisations, but noted that Beijing-linked groups typically persist until they succeed. The campaign illustrates how AI policy itself has become an intelligence target: rather than steal model weights, the operators sought access to the experts shaping export controls and the military use of AI, where email inboxes can be as valuable as the technology they discuss.

Timeline

  1. TA419 impersonates a senior Anthropic employee to target an AI policy analyst at a US think tank, using the subject line referencing military integration of Anthropic's Claude models.

  2. TA419 launches expanded credential-phishing campaigns impersonating former US officials Lynne Edwards Parker and Heidi Crebo-Rediker.

  3. Proofpoint publicly details the campaign in a report authored by analyst Mark Kelly.

Sources

  1. helpnetsecurity.comhttps://www.helpnetsecurity.com/2026/10/02/china-aligned-ta419-phishing-ai-policy-experts/
  2. cnn.comhttps://www.cnn.com/2026/10/01/politics/china-linked-hackers-impersonated-us-ai-insiders
  3. aljazeera.comhttps://www.aljazeera.com/economy/2026/10/1/chinese-hackers-impersonated-ai-experts-to-target-us-policy-minds
  4. nextgov.comhttps://www.nextgov.com/cybersecurity/2026/10/china-linked-hackers-posed-former-us-officials-anthropic-employee-target-ai-experts/416356/

Related incidents

EspionageContained

Salt Typhoon US telecom espionage campaign (2024)

China-linked Salt Typhoon infiltrated at least nine U.S. telecom providers โ€” Verizon, AT&T, T-Mobile, Spectrum, Lumen, Consolidated, Windstream โ€” including the CALEA lawful-intercept systems used for court-authorised wiretaps. Metadata for over a million users was exposed; the U.S. Treasury sanctioned a linked PRC contractor.

Victim
U.S. telecommunications providers (Verizon, AT&T, T-Mobile, Spectrum, Lumen, Consolidated Communications, Windstream)
EspionageContained

Microsoft Storm-0558 signing-key theft and US government email access (2023)

China-based Storm-0558 forged authentication tokens using a stolen Microsoft consumer signing key and read email at approximately 25 organisations โ€” including the US State Department, the Department of Commerce, and the U.S. Ambassador to China. The 'cascade of errors' that enabled it became a defining case for cloud-provider key custody.

Victim
Microsoft customers (US State Department, Department of Commerce, ~25 organisations)
EspionageResolved

Democratic National Committee hack

Russian GRU Units 26165 (APT28) and 31165 (APT29) compromised the Democratic National Committee, Hillary Clinton campaign, and DCCC. Stolen emails were selectively released via 'DCLeaks', 'Guccifer 2.0', and WikiLeaks to influence the 2016 U.S. presidential election.

Victim
Democratic National Committee + Clinton campaign + DCCC
Loss
$50.0M
Records
50.0K