China-Linked Group TA419 Uses Fake Colleagues and Fake Microsoft Logins to Target AI Policy Experts
A China-aligned espionage group known as TA419 has been tied to multiple credential phishing campaigns aimed at artificial intelligence experts at U.S. think tanks, universities and legal sector organisations. Proofpoint, which published the analysis, says the activity likely supports wider Chinese intelligence goals of understanding U.S. AI policy and regulation. It describes the group as having targeted think tanks, defence contractors, universities and law firms in the U.S. and Japan since at least April 2025.
The attackers impersonate people their targets would trust, including prominent economists, AI policymakers, a prominent Anthropic employee and a former member of the White House Office of Science and Technology Policy leadership team. In one February 2026 case, an AI policy expert at a U.S. think tank received an email titled "Request for Feedback on Military Integration of Claude."
The approach is patient. The first message is a harmless invitation designed to build trust. Only after the recipient replies does the attacker send a shortened link. It leads through several redirects and a Cloudflare Turnstile check to a fake OneDrive login page that captures credentials. The page uses a technique called Frameless BitB, which draws a fake browser window inside a real one to imitate a trusted login screen. Although the targets here are specialised, the same tactics of impersonation, trust-building and convincing fake logins can be used against any business.