Skip to content
Chinese TA419 Group Targets AI Policy Experts with Phishing Campaigns

Chinese TA419 Group Targets AI Policy Experts with Phishing Campaigns

First seen 6 Oct 2026, 09:26 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 6, 2026 at 11:27 UTC
  • •TA419 is targeting U.S. AI policy experts using sophisticated phishing techniques.
  • •The group impersonated credible figures, including a former OSTP official, to gain trust.
  • •Microsoft AitM techniques were used to bypass multifactor authentication.

The Chinese cyberespionage group TA419 has been targeting U.S. AI policy experts through credential phishing campaigns. These attacks, documented by Proofpoint, involved impersonating a former White House OSTP official and prominent economists to gain access to sensitive accounts. The phishing tactics employed included the use of Microsoft AitM (Adversary-in-the-Middle) techniques, allowing attackers to intercept credentials even with multifactor authentication. The campaigns, which began in July 2026, aimed to compromise experts at think tanks and universities, providing strategic insights into regulatory frameworks and technological competition between the U.S. and China. The operation reflects a shift in TA419's focus towards high-value targets within the AI policy domain, indicating a growing interest in influencing AI governance and research. Current status indicates ongoing threats as the group continues to refine its tactics.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-07-01
Phishing campaigns initiated
TA419 began targeting AI policy experts in the U.S. using credential phishing tactics.
Ciberseguridadlatam
2026-10-03
Details of phishing tactics revealed
Proofpoint documented the use of impersonation tactics by TA419, highlighting the targeting of AI experts.
Ciberseguridadlatam
2026-10-06
New report on TA419's activities
Ciberseguridadlatam published an article detailing ongoing phishing campaigns targeting AI policy experts.
Ciberseguridadlatam

More articles in this cluster (2)

Following this threat?

Track APT41 and Anthropic in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Who is targeted by TA419?
TA419 is targeting U.S. experts in AI policy, including those at think tanks and universities.
What methods are being used in these attacks?
The group is using credential phishing, impersonating credible figures to gain trust and access.
How can organizations protect themselves?
Organizations should enhance their email security protocols and educate staff on recognizing phishing attempts.