Infosecurity-Magazine China-Aligned TA419 Targets US AI Experts in Phishing Campaign
Article Content
- •TA419 impersonated U.S. AI experts to conduct phishing attacks targeting policy analysts.
- •The phishing emails were designed to build rapport before redirecting victims to credential-stealing sites.
- •The campaign reflects ongoing geopolitical tensions between the U.S. and China over AI development.
In July 2026, the China-aligned threat actor TA419 conducted credential phishing campaigns targeting AI policy experts in the U.S. by impersonating prominent figures, including Lynne Parker and Heidi Crebo-Rediker. The attackers sent benign emails inviting recipients to join a fictitious AI Policy Advisory Committee, which led to a multi-stage URL redirection to a credential phishing page designed to steal login credentials. This operation is part of a broader intelligence-gathering effort by China amid ongoing competition over AI technology. Proofpoint has tracked TA419's activities since April 2025, noting that the group has previously targeted individuals in U.S. and Japanese think tanks, defense contractors, and universities. The phishing method utilized a modified version of the Frameless BitB tool, which creates a deceptive login interface. The campaign's impact is still being assessed, with no confirmed account compromises reported.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (40)
Following this threat?
Track TA419 and Anthropic in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Who are the primary targets of TA419?
What phishing techniques are being used?
Is there evidence of successful compromises?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…