A suspected Chinese espionage group impersonated AI policy figures in July phishing campaigns. The attackers targeted AI policy experts at US universities, think tanks, and law firms. Security researchers say the targets included a senior Anthropic employee and a former White House official.
Proofpoint discovered the espionage attempts and attributed them to a China-aligned group tracked as TA419. Mark Kelly, a Proofpoint threat-intelligence analyst, shared details in a Thursday report. The alert arrived one day after OpenAI accused China-based Moonshot AI of stealing American model data through distillation attacks starting July 1.
Spies offered fake advisory committee roles
TA419 impersonated multiple individuals in July 2026. This included a former member of the White House Office of Science and Technology Policy leadership team. Beginning July 8, the group sent emails spoofing Lynne Edwards Parker, the former principal deputy director of that office. They also spoofed Heidi Crebo-Rediker, a prominent economist and foreign policy expert.
The emails invited targets to join a fake AI policy advisory committee. Alternatively, they asked targets to contribute to a Senate foreign relations committee report on AI export controls and supply chains. When American experts replied, the operators sent a shortened URL pointing to an attacker-controlled domain.
Phishing chains targeted cloud credentials
The malicious page used a Cloudflare Turnstile check behind a phony OneDrive loading screen. It then redirected victims to an attacker-in-the-middle credential phishing page to steal cloud account login information. The July 2026 campaigns used driftshare.co as the first-stage domain and globalfileshareplatform.com as the second-stage domain.
In February, the Chinese spies spoofed a senior Anthropic employee to phish an AI policy analyst at a US think tank. That email used the subject line requesting feedback on the military integration of Claude. This occurred while US military officials pressured Anthropic to remove Claude safety safeguards.
Read nextSony Brings QSSR AI Upscaling Tech to Standard PS5 ConsolesAttackers used open source kits
TA419 targets Microsoft 365 and Entra ID through the first-party OfficeHome application. The framework relies on open source Frameless BitB. This contains a Browser-in-the-Browser overlay and an Evilginx phishlet to intercept usernames, passwords, and session cookies. Server-side substitution rules inject the kit into proxied pages.
The group typically uses Cloudflare content delivery networks to hide backend hosting IP addresses. Their domains frequently mimic file sharing sites and cloud services like msfile.online and onecloudfilesync.com. They also impersonate organizations including the Japan-Taiwan Exchange Association, The Heritage Foundation, and Japanese Minister of Defense Shinjirō Koizumi’s official website.
Proofpoint published dozens of phishing and spoofed-sender domains alongside registration timelines in its report. Threat hunters warn that TA419 and other Beijing-aligned crews will likely continue targeting policy experts working on technologies of interest to the Chinese government. Organizations in the scope of TA419 activity should consider phishing-resistant, origin-bound authentication such as passkeys.



