{"slug": "ai-policy-circles-targeted-in-china-linked-phishing-operation", "title": "AI policy circles targeted in China-linked phishing operation", "summary": "Proofpoint attributed a China-aligned phishing operation it calls TA419 to attacks on U.S. artificial intelligence policy experts at think tanks, universities and law firms, using emails that impersonated former White House Office of Science and Technology Policy principal deputy director Lynne Parker, economist Heidi Crebo-Rediker and a senior Anthropic employee. The group used a modified version of the open-source Frameless BitB tool to present a fake Microsoft login window over a page resembling a OneDrive document-sharing site, capturing credentials and active browser sessions in an adversary-in-the-middle attack, and has targeted individuals connected to U.S. and Japanese think tanks, defense contractors, universities and law firms since at least April 2025. The report did not identify victims or state whether any accounts were compromised, and did not directly link the activity to the Chinese government.", "body_md": "# AI policy circles targeted in China-linked phishing operation\n\nA China-aligned cyber espionage group targeted U.S. artificial intelligence policy experts through [phishing](https://cyberscoop.com/tag/phishing/) emails that impersonated prominent officials, economists and an employee of AI company Anthropic, according to research released Thursday by Proofpoint.\n\nThe campaigns, which the cybersecurity company attributed to a group it calls TA419, sought access to cloud accounts held by people at think tanks, universities and law firms. The activity comes amid growing U.S.-China competition over [AI](https://cyberscoop.com/tag/artificial-intelligence-ai/) development, export controls, semiconductor supply chains and military uses of the technology.\n\nProofpoint said the group began a campaign in July by impersonating [Lynne Parker](https://fedscoop.com/lynne-parker-dean-ball-exit-white-house-following-publication-ai-plan/), a former principal deputy director of the White House Office of Science and Technology Policy, and economist and foreign policy expert Heidi Crebo-Rediker. The emails invited recipients to join a supposed AI policy advisory committee or contribute to a report on AI export controls and supply chains.\n\nThe initial messages did not immediately request passwords or direct recipients to a sign-in page. Instead, they appeared designed to begin a conversation and establish trust. After a target replied, the group sent a shortened link said to contain more information.\n\nThe link redirected recipients through several websites before leading to a false Microsoft OneDrive sign-in page. Proofpoint said the setup was intended to capture account credentials and active browser sessions.\n\nThe firm described the operation as an adversary-in-the-middle phishing attack. In such attacks, the victim interacts with genuine [Microsoft](https://cyberscoop.com/tag/microsoft/) infrastructure during part of the process, looking and behaving like a legitimate sign-in. The person may enter a password, complete a multifactor authentication prompt and pass access checks while the attacker captures the session information created by the login.\n\n[Proofpoint](https://cyberscoop.com/tag/proofpoint/) said TA419 used a modified version of an open-source phishing tool known as [Frameless BitB](https://github.com/waelmas/frameless-bitb). The tool creates a false browser window within a webpage, imitating a familiar sign-in prompt. In this case, it was used to present a fake Microsoft login window over a page that resembled a OneDrive document-sharing site.\n\nProofpoint also identified a February campaign in which the same group impersonated a senior Anthropic employee. That message asked an AI policy analyst at a U.S. think tank for feedback on the military’s use of [Anthropic](https://cyberscoop.com/tag/anthropic/)’s Claude AI models, which was a highly controversial topic at time.\n\nThe report did not identify victims or state whether any accounts were compromised.\n\nProofpoint said TA419 has targeted individuals connected to U.S. and Japanese think tanks, defense contractors, universities and law firms since at least April 2025. Its interest in AI policy, the firm said, appears to extend an existing focus on defense, national security, energy, international relations and foreign policy. The group also registered domains resembling real organizations, including the Heritage Foundation, the World Economic Forum and the Japan-Taiwan Exchange Association.\n\nThe report does not directly link the activity to the Chinese government. China has repeatedly denied conducting cyber espionage, while accusing the United States of cyber operations against Chinese interests.\n\nThe White House, along with several AI companies, have also accused China of distilling U.S. models in order to power open-weight models run by Chinese companies.\n\nIndicators of compromise can be found [on Proofpoint’s website](https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy).", "url": "https://wpnews.pro/news/ai-policy-circles-targeted-in-china-linked-phishing-operation", "canonical_source": "https://cyberscoop.com/china-cyber-espionage-ta419-phishing-us-ai-policy-experts/", "published_at": "2026-10-01 14:06:19+00:00", "updated_at": "2026-10-01 14:20:15.159782+00:00", "lang": "en", "topics": ["ai-policy", "ai-safety"], "entities": ["Proofpoint", "TA419", "Anthropic", "Claude", "Lynne Parker", "Heidi Crebo-Rediker", "Microsoft", "White House Office of Science and Technology Policy"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/ai-policy-circles-targeted-in-china-linked-phishing-operation", "markdown": "https://wpnews.pro/news/ai-policy-circles-targeted-in-china-linked-phishing-operation.md", "text": "https://wpnews.pro/news/ai-policy-circles-targeted-in-china-linked-phishing-operation.txt", "jsonld": "https://wpnews.pro/news/ai-policy-circles-targeted-in-china-linked-phishing-operation.jsonld"}}