What happened

A China-nexus espionage actor is linked to a series of credential phishing campaigns aimed at AI policy experts in the United States, according to research published by Proofpoint. The group, tracked as TA419, impersonated leading economists and AI policymakers. In a July campaign it posed as people its targets would recognise, and in a February attack it pretended to be an Anthropic employee to reach an AI policy analyst at a U.S. think tank.

The lures were low key. They arrived as routine emails inviting the target to join an advisory committee on AI policy. Once a target replied, the actor moved to an adversary-in-the-middle attack using a browser-in-the-browser phishing tool called Frameless BitB. The attacks targeted Microsoft 365 and Entra ID through a first-party OfficeHome application, which is the kind of sign-in flow users are trained to trust.

Proofpoint says the impersonation went deep. In July the actor posed as Lynne Parker, a former principal deputy director at the White House Office of Science and Technology Policy, and later as Heidi Crebo-Rediker, an economist and foreign policy expert. The February lure, sent while pretending to be an Anthropic executive, asked for information on military use of the company's Claude models.

TA419 has been active since at least April 2025 and has targeted think tanks in the U.S. and Japan, along with defense contractors, law firms and universities. According to Proofpoint, the actor used Cloudflare's content delivery network to hide its backend hosting and registered domains through a hosting provider called NameSilo. The campaign sits alongside other China-linked activity, including a CISA warning last month about industrial-scale knowledge distillation campaigns against U.S. AI companies.

Why this is a GRC story

Identity is the control that failed. An adversary-in-the-middle attack captures the session after authentication, so a password and a prompt for a second factor are not enough on their own. Conditional access, token protection and device posture are the controls that decide whether a stolen session can be used.

The target list is the risk statement. The people being phished hold views on AI regulation before those views are public. If your organisation talks to government, hosts advisory panels or briefs policymakers, those conversations are an intelligence target, not just an administrative task.

A trusted vendor name is a lure, not a defence. Impersonating a well-known AI company borrows its credibility. Staff who would question an odd internal request will answer a plausible external one, especially when it appears to come from a name they respect.

What to watch

Watch whether the same tradecraft spreads to other policy areas. The pattern, impersonating real people and inviting the target onto a committee, works wherever there is a live policy debate and a small pool of expert voices.

The practical move is to check what a stolen mailbox would be worth. If senior staff can reach strategy documents, board papers or unreleased research from email alone, that is the exposure to reduce. It is worth reading Proofpoint's technical report alongside your own conditional access and token protection settings, because the controls it bypasses are the ones most organisations have already bought and not yet tuned.

Attribution: Analysis based on Cybersecurity Dive's reporting and Proofpoint's research. This article is original commentary, not a repost of the source material.

More daily case studies
← Back to GRC News