A China-aligned espionage group spent months posing as AI policy insiders to steal the Microsoft account credentials of researchers who shape US technology policy. Proofpoint, the email security company, published its findings on 1 October, describing campaigns by a group it tracks as TA419 that impersonated Lynne Edwards Parker, a former principal deputy director of the White House Office of Science and Technology Policy, the economist Heidi Crebo-Rediker, and a senior Anthropic employee.
The targets were AI policy specialists at think tanks, universities and law firms, people whose work covers export controls, national security and the regulation of AI. Proofpoint has tracked the group against similar targets in the US and Japan since at least April 2025.
The lures were built for that audience. Recipients were invited to join a fictitious "AI Policy Advisory Committee," asked to contribute to a Senate Foreign Relations Committee report on AI export controls, or approached about military use of Anthropic's Claude models.
How The Attack Worked
TA419 did not send malware. It ran credential phishing designed to defeat multi-factor authentication, using a technique known as adversary-in-the-middle, where the attacker's server sits between the victim and the real login page and relays everything in both directions.
The group began with ordinary conversation, exchanging messages to establish trust before sending a link. That link passed through URL shorteners to domains the attackers controlled, hidden behind Cloudflare, dressed up as file sharing and cloud storage services with names such as driftshare.co. Victims arrived at what looked like a Microsoft sign-in page for a shared OneDrive folder.
It was not a page. The attackers used Frameless BitB, an open-source tool that draws a convincing fake browser window inside a web page, complete with what appears to be a real address bar. Behind it, their server proxied the genuine Microsoft OAuth2 login in real time, captured the password, handled the multi-factor prompt and took the resulting session cookie.
Why That Beats Most MFA
A stolen session cookie is the prize. It represents an already-authenticated session, so an attacker who replays it is inside the account without needing the password or a second factor again.
This is why one-time codes, whether from an app or a text message, offer limited protection against this class of attack: the victim enters the code into the fake page, and the attacker passes it straight to Microsoft. Proofpoint's first recommendation is phishing-resistant authentication such as passkeys or hardware security keys, which are bound to the real website's address and simply will not produce a valid response for an attacker's domain.
The group also built telemetry into its tooling, tracking how far each victim had progressed through the sign-in flow, and injected fake OneDrive folder listings into the page to keep the pretence going.
Why AI Policy Experts
The target selection says something about what China's intelligence services want to understand. Proofpoint assesses the activity likely supports efforts to track developments in US AI policy and regulation, extending TA419's existing interest in defence, national security, energy and foreign relations.
That is a reasonable thing to want. US decisions on chip export controls, on cloud access to advanced models, and on what AI capabilities may be sold abroad have direct consequences for Chinese technology companies, and much of the thinking behind those decisions circulates among a small group of researchers and lawyers long before it reaches public documents.
Think tanks and law firms also make softer targets than government agencies. They hold sensitive drafts and correspondence, they run on standard cloud email, and they rarely have the security budgets of the agencies whose policy they influence.
What Organisations Should Change
Proofpoint's advice is short and worth acting on. Organisations whose staff work on sensitive policy should move to phishing-resistant authentication, since that single change neutralises the technique at the centre of this campaign.
The second recommendation is procedural: verify unsolicited approaches from subject-matter experts through a separate channel before engaging. An invitation to join a committee or contribute to a report, arriving from a name the recipient recognises, is exactly the kind of message that gets a reply, and a short check against a known contact detail defeats the impersonation before any link is clicked.
The wider lesson for any organisation is that credential phishing has moved well past badly written emails. These messages were researched, patient and built around real people and plausible institutions, which is also the direction security regulation is heading, as the obligations under the EU's Cyber Resilience Act make clear for product makers.
Expertise Has Become The Disguise
TA419's method required no technical breakthrough. The tooling is open source, the infrastructure is commodity hosting behind a content delivery network, and the technique for defeating multi-factor authentication has been documented for years.
What made it work was credibility. By borrowing the identities of people whose names open doors in AI policy, and by inventing a committee that sounded like something a researcher would want to join, the group turned the small, trusting world of policy expertise into its attack surface. Proofpoint expects more of it, and the defence that actually holds is the unglamorous one: authentication that cannot be relayed, and a habit of checking who is really writing.