Skip to content
China-Aligned TA419 Targets US AI Experts in Phishing Campaign

China-Aligned TA419 Targets US AI Experts in Phishing Campaign

First seen 1 Oct 2026, 15:02 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 2, 2026 at 14:09 UTC
  • •TA419 impersonated U.S. AI experts to conduct phishing attacks targeting policy analysts.
  • •The phishing emails were designed to build rapport before redirecting victims to credential-stealing sites.
  • •The campaign reflects ongoing geopolitical tensions between the U.S. and China over AI development.

In July 2026, the China-aligned threat actor TA419 conducted credential phishing campaigns targeting AI policy experts in the U.S. by impersonating prominent figures, including Lynne Parker and Heidi Crebo-Rediker. The attackers sent benign emails inviting recipients to join a fictitious AI Policy Advisory Committee, which led to a multi-stage URL redirection to a credential phishing page designed to steal login credentials. This operation is part of a broader intelligence-gathering effort by China amid ongoing competition over AI technology. Proofpoint has tracked TA419's activities since April 2025, noting that the group has previously targeted individuals in U.S. and Japanese think tanks, defense contractors, and universities. The phishing method utilized a modified version of the Frameless BitB tool, which creates a deceptive login interface. The campaign's impact is still being assessed, with no confirmed account compromises reported.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-07-08
Phishing campaign launched
TA419 began sending phishing emails impersonating Lynne Parker and Heidi Crebo-Rediker to AI policy experts in the U.S.
Proofpoint
2026-10-01
Proofpoint report published
Proofpoint released findings detailing TA419's phishing operations targeting AI experts, marking the first public report on the group.
Cyberscoop

More articles in this cluster (40)

Following this threat?

Track TA419 and Anthropic in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Who are the primary targets of TA419?
TA419 primarily targets AI policy experts at U.S. think tanks, universities, and law firms.
What phishing techniques are being used?
The attackers use a multi-stage URL redirection to a credential phishing page, employing a modified Frameless BitB tool.
Is there evidence of successful compromises?
As of now, there are no confirmed reports of account compromises from this phishing campaign.