A cybersecurity firm has exposed a Chinese intelligence-linked hacking campaign that borrowed the most convincing disguise available: real people with real reputations in AI policy.
Proofpoint said on 1 October that a threat actor it tracks as TA419 ran multiple credential-phishing campaigns in July 2026, impersonating Lynne Parker — the former principal deputy director of the White House Office of Science and Technology Policy — and Heidi Crebo-Rediker, an economist and foreign-policy expert. The targets were AI policy specialists at US think tanks, universities and law firms.
The approach was patient. The hackers opened with plausible professional outreach, inviting targets to join a fictitious "AI Policy Advisory Committee" or to contribute to a Senate Foreign Relations Committee report on AI export controls and supply chains. Only when a target replied did they send a link that led, through a chain of redirects, to a fake OneDrive login page built to steal credentials.
Proofpoint said the chain used an adversary-in-the-middle kit based on the open-source Frameless BitB browser-in-the-browser tool, targeting Microsoft 365 and Entra ID. A custom script tracked and drove the victim's progress through the sign-in flow, auto-accepting "keep me signed in" and submitting one-time codes to extend a stolen session.
The campaign was not the group's first strike at AI policy. In February 2026, TA419 impersonated a senior employee of the AI company Anthropic, using the subject line "Request for Feedback on Military Integration of Claude" to approach an AI policy analyst at a US think tank. Proofpoint says the group has targeted US and Japanese think tanks, defence contractors, universities and law firms since at least April 2025.
Reuters reported fewer than 10 people were targeted in the latest wave, one of them Alex Engler, a former White House official now at the University of Pennsylvania, who grew suspicious and warned colleagues. Proofpoint said it found no evidence the attacks succeeded, but cautioned that its visibility may not cover the whole campaign. Its advice is blunt: treat unsolicited subject-matter outreach as a possible pretext, verify through a second channel, and adopt phishing-resistant authentication such as passkeys.
Sources
- proofpoint.comHallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles (Proofpoint)
- aljazeera.comChinese hackers impersonated AI experts to target US policy minds (Al Jazeera)
- cyberscoop.comAI policy circles targeted in China-linked phishing operation (CyberScoop)
- cybersecuritydive.comState-linked actor targets US AI policy experts in credential phishing (Cybersecurity Dive)




