China-Linked Group Impersonates Government Officials to Target AI Policy Specialists

Researchers at Proofpoint identified a Chinese state-aligned espionage group called TA419 conducting sophisticated phishing campaigns against U.S. AI policy experts in July 2026. The group impersonated a former White House Office of Science and Technology Policy official and other prominent figures to create fake credential phishing pages that captured login credentials and multi-factor authentication codes. The attackers used multi-stage social engineering tactics, beginning with innocent-looking emails about policy committees that escalated to credential harvesting through convincing OneDrive spoofing.
TA419's campaign demonstrates how state-sponsored actors exploit trust networks within policy circles. By impersonating respected figures like former White House officials and economists, the group bypassed initial skepticism that generic phishing attempts often encounter. The attackers then employed layered technical deception, routing targets through multiple domains and using legitimate services like Cloudflare to hide their infrastructure before presenting a convincing replica of Microsoft's authentication system.
The group's operational pattern reveals sustained interest in U.S. artificial intelligence governance. Beyond the July 2026 campaigns targeting policy experts, TA419 had previously impersonated Anthropic staff in February, suggesting coordinated intelligence collection around American AI companies and their regulatory frameworks. Domain registrations mimicking organizations like the Heritage Foundation and Japanese government officials indicate the group's broader espionage activities extend across multiple geopolitical interests.
This campaign could affect how U.S. policymakers, researchers, and technology sector employees approach email security and authentication protocols. Compromised cloud accounts may expose sensitive policy discussions, strategic analyses, and internal communications about AI regulation—information that could inform foreign intelligence assessments. The targeting of policy specialists may influence their ability to work openly, potentially chilling candid exchanges needed for sound governance. Organizations handling AI policy may face increased pressure to implement stricter security measures, affecting operational efficiency.