Adversary Intelligence — 2026-10-04
China-Aligned TA419 Hackers Impersonate Former US Officials and Anthropic Employee to Steal AI Policy Researchers Credentials
BLUFTA419's pivot to AI policy lures will likely yield further impersonation campaigns against US and allied researchers through 2026, and only phishing-resistant authentication defeats the session-cookie theft after MFA succeeds.
Proofpoint reported on October 1 that the China-aligned actor it tracks as TA419 began impersonating former White House OSTP deputy director Lynne Parker, then economist Heidi Crebo-Rediker, on July 8, inviting AI policy experts at US think tanks, universities and law firms to join a fictitious "AI Policy Advisory Committee" or contribute to a Senate Foreign Relations report 12. Replies received a shortened link to a fake OneDrive adversary-in-the-middle page built on a modified Frameless BitB kit, designed to capture Microsoft 365 session cookies 13. Proofpoint also said TA419 impersonated an unnamed senior Anthropic employee in February, emailing a think-tank analyst under the subject "Request for Feedback on Military Integration of Claude" 12. Parker told Nextgov/FCW she learned of the impersonation on July 9 from two recipients. Crebo-Rediker and Anthropic did not respond, and the report does not state how many were targeted or whether any accounts were compromised 24.
AnalysisTA419's shift into AI policy circles puts private US deliberations on export controls and military use within reach of Chinese intelligence collection. Because the kit relays genuine Microsoft sign-in and captures session cookies after MFA succeeds, phishing-resistant, origin-bound authentication is the decisive control. The initial lure is a benign, link-free email, so filters have little to catch. We assess TA419 will
likely keep impersonating real subject-matter experts against policy researchers in the US and Japan through the end of 2026. Confidence is moderate: the tradecraft detail is strong, but everything traces to one Proofpoint report that the other outlets merely repeat, and no victim count or confirmed compromise exists. The campaigns may instead be broad rapport-building for long-term access, with AI themes reflecting a reused playbook rather than a new collection priority. Institutions should treat authentication mandates as urgent, and a post-disclosure pause would not justify relaxing them.
5 sources
- Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles - Proofpoint
- China-linked hackers posed as former US officials, Anthropic employee to target AI experts - Nextgov/FCW
- Chinese spies impersonate White House, Anthropic figures to phish AI policy experts - Help Net Security
- AI policy circles targeted in China-linked phishing operation - CyberScoop
- Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles - Proofpoint
View in full brief →