cd /news/ai-policy/suspected-chinese-spies-spoofed-an-a… · home › topics › ai-policy › article
[ARTICLE · art-143349] src=machinebrief.com ↗ pub= topic=ai-policy verified=true sentiment=↓ negative

Suspected Chinese spies spoofed an Anthropic exec, ex-White House official in AI phishing

Proofpoint attributed a July 2026 credential-phishing campaign targeting US AI policy experts at universities, think tanks and law firms to a China-aligned group it tracks as TA419, which spoofed former White House Office of Science and Technology Policy principal deputy director Lynne Edwards Parker and economist Heidi Crebo-Rediker. Proofpoint threat-intelligence analyst Mark Kelly said TA419 impersonated multiple individuals, including a former member of the White House OSTP leadership team, and lured targets with fake AI policy advisory committee invitations and a purported Senate foreign relations committee report on AI export controls. The campaign used driftshare[.]co and globalfileshareplatform[.]com and an attacker-in-the-middle page built on open source Frameless BitB with an Evilginx phishlet to steal Microsoft 365 usernames, passwords and session cookies, following a February campaign that spoofed a senior Anthropic employee with the subject line "Request for Feedback on Military Integration of Claude.

read3 min views1 publishedOct 1, 2026
Suspected Chinese spies spoofed an Anthropic exec, ex-White House official in AI phishing
Image: Machinebrief (auto-discovered)

Source:

The Register Your invite to a fake AI policy advisory committee has strings attached

A suspected Chinese espionage group impersonated

AI policyfigures, including a seniorAnthropicemployee and a former White House official, in phishing campaigns targeting AI policy experts at US universities, think tanks, and law firms, security researchers say. The bulk of these campaigns occurred in July, according to Proofpoint, which discovered the espionage attempts and attributed them to a China-aligned group it tracks as TA419. Proofpoint’s security alert comes a day afterOpenAIaccused China’s Moonshot AI of stealing the American models’reasoningand other data indistillationattacks that began on July 1. “In July 2026, TA419 impersonated multiple individuals, including a former member of the White House Office of Science and Technology Policy leadership team, in credential phishing campaigns targeting AI policy experts in the US,” Proofpoint threat-intelligence analyst Mark Kelly said in a Thursday report. Beginning July 8, TA419 sent phishing emails spoofing Lynne Edwards Parker, the former principal deputy director of the White House Office of Science and Technology Policy, and then Heidi Crebo-Rediker, a prominent economist and foreign policy expert, to even more American AI policy experts at think tanks, universities, and law firms. The suspected spies’ emails invited their targets to join a fake AI policy advisory committee or contribute to a Senate foreign relations committee report on AI export controls and supply chains. If the American AI expert replied, the Beijing-linked crew responded with a shortened URL promising to share additional details, but in reality pointing to an attacker-controlled domain. This page conducts a Cloudflare Turnstile check behind a phony OneDrive screen, and then redirects the victim to an attacker-in-the-middle (AitM) credential phishing page that steals the victim’s cloud account login information. The July 2026 campaigns used driftshare[.]co as the first-stage domain and globalfileshareplatform[.]com as the second-stage domain. In February - as US military officials pressured Anthropic to removeClaude’s safeguards - the Chinese spies spoofed a senior Anthropic employee to phish an AI policy analyst at a US think tank. This email used the subject line: “Request for Feedback on Military Integration of Claude.” TA419’s phishing chain targets Microsoft 365/Entra ID through the first-party OfficeHome application (client_id=4765445b-32c6-49b0-83e6-1d93765276ca). It’s built on open source Frameless BitB, which contains a Browser-in-the-Browser (BitB) overlay, an Evilginx phishlet to intercept usernames, passwords, and session cookies for Microsoft 365, and server-side substitution rules that inject the kit into proxied pages. TA419 typically uses Cloudflare’s content delivery network to hide the backend hosting IP address for its domains, and its credential phishing domains are usually themed around file sharing sites and cloud services - such as msfile[.]online and onecloudfilesync[.]com. It also impersonates specific organizations, including the Japan-Taiwan Exchange Association (tw-koryu[.]org), The Heritage Foundation (heritiages[.]org and heritiage[.]org), and Japanese Minister of Defense Shinjirō Koizumi’s official website (shinjirou[.]info). In total, the crew uses dozens of phishing and spoofed-sender domains, and phony email addresses. Proofpoint includes all of the ones it discovered in 2026, plus the timeline of when they were registered or first seen, so check out those indicators, too. TA419 and other Beijing-aligned crews will likely continue targeting AI and other policy experts working on technologies of interest to the Chinese government, according to the threat hunters. “Organizations in the scope of TA419 activity should consider phishing-resistant, origin-bound authentication such as passkeys,” they recommend.® Get AI news in your inbox

Daily digest of what matters in AI.

── more in #ai-policy 4 stories · sorted by recency
── more on @proofpoint 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/suspected-chinese-sp…] indexed:0 read:3min 2026-10-01 · —