A China-aligned group tracked as TA419 impersonated well-known AI policy figures to phish U.S. and Japanese researchers. Proofpoint disclosed the campaign on October 1, 2026.
The goal looks like policy intelligence. Nobody has shown that any data was stolen.
What Happened
Proofpoint has watched TA419 since at least April 2025. Targets include think tanks, universities, defense contractors, and law firms.
Two lure waves stand out:
- February 2026: Operators posed as an Anthropic employee and pitched a discussion about military use of Claude.
- From July 8, 2026: Operators impersonated Lynne Parker and Heidi Crebo-Rediker. The invitations covered an AI advisory committee and a Senate foreign relations report on export controls and supply chains.
Reuters independently identified Alex Engler as a target. He checked the outreach with professional contacts and spotted the fake.
How the Attack Works
The first message is harmless. It asks for expertise.
The malicious part comes after the target replies:
- A shortened link opens a page with fake OneDrive branding.
- A fake browser window appears inside the page. This is browser-in-the-browser deception.
- The login routes through an adversary-in-the-middle proxy.
- The proxy relays the real Microsoft sign-in and captures the session cookie.
The victim completes a genuine login. The attacker keeps the session.
Why MFA Codes Don’t Save You Here
The proxy passes SMS codes, app codes, and push approvals straight through. Phishing-resistant methods like FIDO/WebAuthn are different. They bind to the real domain, so a relayed login fails. CISA recommends them.
Still, passkeys and security keys are one layer, not a full fix.
What We Don’t Know
- Victim count: Proofpoint saw fewer than ten people at a handful of organizations. That is its visibility, not a total.
- Data theft: No evidence of stolen emails or documents has been published.
- Attribution: “China-aligned” is Proofpoint’s assessment. No agency has been named.
- Zero-days and AI-written lures: Neither is established by the reporting.
Defender Checklist
- Verify unexpected invitations through a contact route you found independently.
- Move high-value users to phishing-resistant authentication first.
- Give staff an easy way to report suspicious outreach, even if nobody clicked.
- Preserve the full message, headers, and link. Don’t revisit the link.
- Review sign-ins, token activity, and inbox rules together after any suspected compromise.
- Revoke sessions along with resetting passwords. Revocation timing varies by application.
Peek Takeaway
Attackers are going after the people around AI policy, not just the labs. Their mailboxes hold draft language and contact lists. Protect them like targets.
Sources:





Leave a Reply