Proofpoint's TA419 phishing campaign targeted U.S. artificial-intelligence policy experts with carefully staged impersonation emails and fake Microsoft 365 sign-in pages. The newly disclosed China-aligned operation focused on people shaping AI regulation, export controls and national strategy rather than model code or computing infrastructure.

 

Proofpoint published its findings on October 1, while Reuters independently identified one recipient and confirmed that fewer than 10 people across a handful of organizations were targeted. The public evidence documents attempted credential theft; it does not establish that TA419 successfully compromised the disclosed targets.

 

The campaign combined four techniques:

  • Impersonation of recognized AI and foreign-policy figures
  • Benign opening messages designed to earn a reply
  • Fake OneDrive pages delivered through shortened links
  • Adversary-in-the-middle interception of Microsoft 365 sessions

 

Proofpoint Uncovers TA419 Phishing Campaign

Proofpoint said TA419 began the latest activity on July 8, impersonating Lynne Edwards Parker, a former principal deputy director of the White House Office of Science and Technology Policy. The group later posed as economist and foreign-policy specialist Heidi Crebo-Rediker.

 

The lures were tailored to the recipients' professional interests. One invited experts to join a fictitious AI Policy Advisory Committee; another sought contributions to a purported Senate Foreign Relations Committee report about AI export controls and supply chains.

 

That personalization made the emails more credible than a generic password-reset warning. The attacker first tried to start an ordinary professional conversation and sent the malicious link only after a recipient responded, reducing the chance that automated filters or a cautious reader would reject the approach immediately.

 

Reuters identified Alex Engler, director of the Penn Center on Media, Technology, and Democracy, as one recipient. Engler said he checked with others after an invitation that appeared to come from Parker felt suspicious. Parker told Reuters that two people received messages impersonating her in early July.

 

How TA419 Turned OneDrive Into a Credential Trap

After a target replied, TA419 sent a shortened URL that passed through attacker-controlled infrastructure. A first-stage domain displayed a fake OneDrive loading screen and Cloudflare Turnstile check before forwarding the visitor to a second domain hosting the credential-phishing system.

 

Proofpoint identified driftshare[.]co as the first-stage domain and globalfileshareplatform[.]com as the second-stage domain in both July campaigns. The second page targeted Microsoft 365 and Entra ID through Microsoft's first-party OfficeHome application.

 

The phishing stack combined Frameless BitB, an open-source browser-in-the-browser kit, with an Evilginx configuration for Microsoft 365. A convincing browser overlay presented attacker-controlled OneDrive content while a proxy relayed the real Microsoft authorization flow behind it.

 

That adversary-in-the-middle design matters because a valid password and one-time code do not necessarily stop the theft. Proofpoint said the proxy allowed the genuine authentication and conditional-access checks to complete while capturing the resulting session cookies, which could let an attacker assume the authenticated session.

 

AI Policy Became the Intelligence Target

Proofpoint has observed TA419 running targeted credential-phishing campaigns since at least April 2025 against people at U.S. and Japanese think tanks, defense contractors, universities and law firms. The company described the group as China-aligned and espionage-motivated based on its infrastructure, tools and target selection.

 

The AI focus predates the July messages. In February, TA419 impersonated a senior Anthropic employee and used a request for feedback about military integration of Claude to approach an AI-policy analyst at a U.S. think tank. That exchange led to a similar credential-phishing chain.

 

Reuters reported that the latest targeting involved fewer than 10 people at a handful of organizations. Proofpoint assessed that the narrow selection indicated an interest in U.S. policymaking rather than technology theft alone. China has long denied conducting cyberespionage, and its Washington embassy did not respond to Reuters' request for comment.

 

The campaign shows why policy discussions can be valuable intelligence even when no source code is involved. Private email may reveal positions under consideration, negotiation priorities, institutional relationships and the timing of decisions on export rules or national AI strategy.

 

Passkeys and Independent Verification Limit the Attack

TA419's method exploits trust between specialists as much as it exploits authentication flows. A recipient may recognize the alleged sender, understand the policy topic and expect documents to arrive through a cloud-sharing service. Each familiar element lowers resistance to the next step.

 

Proofpoint recommends phishing-resistant, origin-bound authentication such as passkeys and verification of unexpected professional outreach through a separate channel. Those controls address different stages: independent contact can expose the impersonation, while origin-bound credentials resist capture by a lookalike site.

 

Organizations also need to treat session cookies as sensitive credentials. Conditional-access monitoring, short session lifetimes, device binding and alerts for unusual sign-ins can reduce the value of a stolen session, although Proofpoint's report did not assess which controls were present at the targeted organizations.

 

The disclosure adds a concrete cyberespionage dimension to competition over AI governance. For researchers, regulators and advisers, the relevant security boundary now includes informal invitations, shared documents and professional networks around policy—not only the laboratories and chips that produce the models.

 

Background Reading