HomeSecurityPhishing: TA419 targets AI Policy experts

Phishing: TA419 targets AI Policy experts

The TA419 spy group , which is allegedly linked to China, attempted to extract login credentials from researchers and experts working on AI policy . Rather than immediately sending an obviously malicious link, it approached targets with invitations to collaborate and only continued the attack when they responded.

Phishing: TA419 targets AI Policy experts

Proofpoint said the July 2026 campaigns targeted experts at U.S. think tanks, universities and law firms . The company is tracking TA419 as a Chinese-aligned actor with espionage motives, but that alone is not proof of the identity or orders of its operators.

See also: 17,000 URLs reveal how ClickFix turns trusted websites into traps

AI policy as bait

The first phishing emails contained no apparent threat. Senders pretended to invite recipients to a nonexistent “Artificial Intelligence Policy Advisory Board” or asked them to contribute to a report on export controls and supply chains. Under this guise, they opened a discussion around issues that really concern those working in the field of AI policy.

According to Proofpoint, TA419 impersonated Lynne Edwards Parker, former deputy director of the White House Office of Science and Technology Policy, and economist Heidi Crebo-Rediker. The company had also documented a previous attempt in February 2026, when the group posed as a senior executive at Anthropic.

This targeting is part of a broader pattern. Proofpoint says it has been tracking TA419 campaigns targeting people at think tanks, defense companies, universities and law firms in the US and Japan since at least April 2025. It believes that the interest in policymaking is broadening, rather than changing, the group's scope of activity.

Misleading calls for artificial intelligence policy

From a response to a fake OneDrive page

The chain was triggered after the target replied to the initial message. It then followed a shortened URL, which went through redirects and ended up on a fake login page posing as OneDrive. In the July campaigns, Proofpoint detected the domains driftshare[.]co and globalfileshareplatform[.]com in successive stages of the path.

The final page involved an adversary-in-the-middle attack: it intervened between the user and the actual login service. The login window was displayed inside another page to make it look familiar. The technique was based on a customized version of the open-source Frameless BitB tool and targeted Microsoft 365 and Entra ID accounts

Because the traffic was forwarded to genuine Microsoft infrastructure, the user could complete the login as normal, while the attacker stole credentials and the active session cookie. Proofpoint also describes a mechanism that monitored the login progress, submitted one-time codes, and automatically opted to stay logged in. So even a multifactor authentication code was not enough to stop the eavesdropping.

See also: Storm-2561 targets corporate VPN users through SEO poisoning

What we know about successful breaches

The disclosure of the technique does not prove that the attackers gained access to specific accounts. Proofpoint describes how login and session data could be collected, but does not provide a number of successful breaches.

This campaign shows why messages that look like regular business invitations need to be vetted, especially when they involve AI policy, exports, or military applications. Experts who receive such requests should verify the sender through a different, already known channel rather than replying to the same thread.

How to reduce the risk

Proofpoint recommends using phishing-resistant authentication methods, such as passkeys. Organizations can also train research and public policy teams to treat unexpected invitations as a potential first stage of an attack. Simply displaying a familiar page or successfully completing multi-factor authentication does not guarantee that a connection is secure.

Access key for work accounts

The SecNews editorial team points out that such attacks exploit trust in real people and current issues, not just technical loopholes. When an AI policy invitation asks for a quick connection or exchange of sensitive information, recipients must verify the request through an independent channel. Neither a familiar logo nor successful verification proves that the website is genuine.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Kimi K3: how Kimi models unlock frontier AI in cybersecurity

The full campaign analysis and technical findings are available in Proofpoint’s research. For potential targets, the key measure is to treat unexpected approaches as unconfirmed until they are verified by an independent source.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS