FindArticles FindArticles
  • News
  • Technology
  • Business
  • Entertainment
  • Science & Health
  • Knowledge Base
FindArticlesFindArticles
Font ResizerAa
Search
  • News
  • Technology
  • Business
  • Entertainment
  • Science & Health
  • Knowledge Base
Follow US
  • Contact Us
  • About Us
  • Write For Us
  • Privacy Policy
  • Terms of Service
FindArticles © 2025. All Rights Reserved.
FindArticles > News > Technology

China-Aligned Phishing Group Targeted US AI-Policy Experts, Proofpoint Says

Bill Thompson
Last updated: October 1, 2026 12:26 pm
By Bill Thompson
Technology
7 Min Read
SHARE

Cybersecurity firm Proofpoint says a threat actor it tracks as TA419 targeted a small group of U.S. artificial-intelligence policy specialists with impersonation-based phishing campaigns, including emails made to appear to come from a former White House science-policy official. The company assesses that the group is aligned with China and that the activity served intelligence-collection interests related to U.S. AI policy.

The campaign is notable less for a confirmed breach than for its choice of targets and its method. Proofpoint documented attempts to obtain Microsoft 365 or Entra ID credentials and authenticated browser sessions from people at think tanks, universities and law firms working on AI regulation, export controls and related policy. Neither Proofpoint’s disclosure nor subsequent reporting establishes that an account was successfully accessed or that emails were taken.

Table of Contents
  • Impersonation aimed at policy specialists
  • Why the login technique can bypass ordinary MFA
  • A campaign with an earlier AI-industry impersonation
Conceptual cloud login screen intercepted between AI policy documents and abstract circuitry

That distinction does not make the attempt routine. The operation paired credible policy-themed correspondence with a phishing system designed to intercept a real Microsoft sign-in process, including after a recipient completed conventional multifactor authentication. It is a reminder that the security value of MFA depends heavily on the kind of MFA deployed and the route a user takes to the login page.

Impersonation aimed at policy specialists

Proofpoint published its technical account on Sept. 30, saying TA419 had been active against organizations in the United States and Japan since at least April 2025. Its broader target list included think tanks, defense contractors, universities and law firms. The July activity narrowed toward people whose work concerns AI policy in the United States.

Beginning July 8, the actor impersonated Lynne Edwards Parker, formerly principal deputy director of the White House Office of Science and Technology Policy, and later economist and foreign-policy specialist Heidi Crebo-Rediker, Proofpoint said. The initial messages were deliberately unremarkable: invitations to a fictitious AI Policy Advisory Committee or requests for contributions to a supposed Senate report on AI export controls and supply chains.

The apparent aim was to start a conversation before presenting a link. A recipient who replied could be sent a shortened URL that passed through redirects and landed on a counterfeit OneDrive page. That sequence makes the email itself only one component of the attack; the social engineering creates enough trust for the victim to enter a sign-in flow that appears familiar.

Reuters reporting carried by Internazionale identified one recipient as Alex Engler, director of the Penn Center on Media, Technology, and Democracy. Engler said an early-July email that seemed to come from Parker looked suspicious after he checked with others. Parker told Reuters that two people had received messages purporting to be from her.

Reuters also reported Proofpoint’s assessment that fewer than 10 people at a handful of organizations were targeted. That limited number is consistent with a tailored collection effort, though the asserted China alignment, espionage motive and connection to Chinese intelligence priorities remain Proofpoint’s assessments, not findings publicly adjudicated by a government agency or court.

Why the login technique can bypass ordinary MFA

Proofpoint said the phishing infrastructure used an adversary-in-the-middle setup, customized with a version of the open-source Frameless BitB tool. Rather than simply displaying a fake password form and collecting a password, such infrastructure can relay a victim’s interaction with a legitimate Microsoft authentication service while observing the credentials, MFA challenge and session data passing through it.

For a cloud account, the valuable prize may be the authenticated session cookie rather than the password alone. Once a legitimate sign-in succeeds, a service gives the browser a session token that tells the service the user has already authenticated. If an attacker captures that token, it may be able to reuse the authenticated session without repeating the user’s MFA step, subject to the service’s session controls, device checks and token expiration.

Diagram showing a phishing proxy relaying a cloud login and capturing an authenticated session token
An adversary-in-the-middle phishing site can relay a real sign-in while attempting to capture the authenticated browser session created after MFA.

This is why an account protected by a texted code or an authenticator-app prompt can still be exposed through a carefully placed proxy. The second factor may verify the user to the real service, but it does not necessarily prevent an intermediary from capturing the resulting session. Proofpoint recommended phishing-resistant, origin-bound authentication methods, including passkeys, alongside security controls that can detect suspicious or unusual session use.

The technique also helps explain why the available evidence should be described precisely. Proofpoint’s infrastructure analysis supports the conclusion that the system was built to capture credentials and session cookies. It does not, by itself, show that the system obtained usable tokens from a particular target, entered a mailbox or removed documents.

A campaign with an earlier AI-industry impersonation

The July operation was not TA419’s first reported use of an AI-related identity. Proofpoint said that in February the group impersonated a senior Anthropic employee in a phishing attempt directed at an AI-policy analyst at a U.S. think tank. The later Parker and Crebo-Rediker lures suggest a repeated interest in the policy community around advanced AI rather than a one-off attempt tied to a single institution.

That sequence is also useful context for the policy subject matter in the messages. Export controls, supply chains, regulation and military applications have become major parts of the competition between Washington and Beijing over AI. Proofpoint’s analysis is that the targeting was likely intended to gather insight into U.S. policy and regulatory thinking, not merely to pursue AI technical secrets.

Beijing has long denied conducting cyberespionage operations, Reuters noted, and the Chinese Embassy did not immediately respond to its request for comment. The public record currently supports a narrower conclusion: a security company has identified a targeted campaign, tied it to its TA419 tracking cluster through malware, infrastructure and targeting patterns, and documented a mechanism capable of intercepting cloud-account sessions. Whether the operation produced usable access remains unconfirmed.

Bill Thompson
ByBill Thompson
Bill Thompson is a veteran technology columnist and digital culture analyst with decades of experience reporting on the intersection of media, society, and the internet. His commentary has been featured across major publications and global broadcasters. Known for exploring the social impact of digital transformation, Bill writes with a focus on ethics, innovation, and the future of information.
Follow Us on Google News
Latest News
Turning Everyday Business Assets Into Simple Marketing Opportunities
White House Announces $6 Billion Science Initiative Package
FDA Clears Tecentriq With Chemotherapy for Stage III dMMR Colon Cancer
SpaceX Agrees to Buy 800 MHz Spectrum for Starlink Mobile
Cut Mix Explained: What’s Actually in a Cutting Blend and Why the Ratios Matter
Measuring AI Visibility Across the Entire Ecommerce Funnel
Why Some Fashion Pieces Stay Relevant Long After Trends Fade
Why Protein Shake Vending Machines Are Becoming a New Revenue Stream for Gyms
How to Choose the Right Hermes Agent VPS for a Growing Business
How to Plan a Safer, Lower-Maintenance Bathroom Remodel
Sam Neill’s Representative Says Pneumonia Caused His Death
FBI, DOJ Seize Microscan and FishHub Access Domains
FindArticles
  • Contact Us
  • About Us
  • Write For Us
  • Privacy Policy
  • Terms of Service
  • Corrections Policy
  • Diversity & Inclusion Statement
  • Diversity in Our Team
  • Editorial Guidelines
  • Feedback & Editorial Contact Policy
FindArticles © 2025. All Rights Reserved.