TA419 and the Claude Impersonation Play: How a China-Aligned Group Phished Its Way Into Washington AI Policy Circles
Introduction
On October 1, 2026, Proofpoint published the first public report on a China-aligned hacking group it tracks as TA419 — and the group's chosen disguise was not malware. It was a mailing list of real, identifiable people whose credibility could be borrowed. Since at least April 2025, Proofpoint says, the group has been sending credential phishing to staff at think tanks, defence contractors, universities and law firms in the United States and Japan, opening conversations in the names of figures including Lynne Parker, the former principal deputy director of the White House Office of Science and Technology Policy, and Heidi Crebo-Rediker, the State Department's first chief economist. Earlier, in February, the same group emailed a US think-tank analyst impersonating a senior Anthropic employee, under the subject line "Request for Feedback on Military Integration of Claude."
What makes TA419 worth reading closely is not the target list. It is the delivery mechanism. Once a recipient replied, the group pushed them through a chain of redirects to a spoofed OneDrive login page that was not a fake form at all — it was a live reverse proxy. Passwords, one-time codes and conditional-access checks all genuinely succeeded, because the victim's own browser was talking to Microsoft in real time while an invisible observer watched.
This matters beyond the intelligence value of a few stolen inboxes. Our coverage of AI governance and the policy fight has tracked export controls, distillation and military use as the strategic fault lines between Washington and Beijing. TA419 is an attempt to read the drafting room rather than the press release.
The campaign: harmless invitations as the pretext stage
The opening messages were, by design, unremarkable. Beginning July 8, the attackers wrote in the names of Parker and Crebo-Rediker, inviting AI researchers to join a fictitious "AI Policy Advisory Committee" or to contribute to a purported report from the Senate Committee on Foreign Relations on AI export controls and supply chains. Neither committee existed.
The pretexts were carefully chosen to be flattering rather than alarming. Parker, an assistant director for AI and founding director of the National AI Initiative Office, was a plausible convener of an AI advisory body. Crebo-Rediker, who now sits as a senior fellow at the Council on Foreign Relations and previously served as chief of international finance and economics for the Senate Foreign Relations Committee, was a plausible recruiter for a report on export controls. A recipient being asked to advise on a topic they already write about would read the request as an ordinary professional opportunity.
Proofpoint's own assessment is blunt about what this stage is for. "Individual targets in scope of TA419 activity should treat unsolicited subject-matter outreach as a plausible pretext stage," the company wrote, advising targets to "seek to verify the legitimacy of such unexpected communications via another independent medium."
That guidance was not theoretical. Parker told Nextgov/FCW that she learned of the impersonation on July 9 — the day after the campaign began — when two recipients, contacted through separate channels, asked her whether she had sent the emails. She told them the messages were fraudulent and alerted colleagues. Her frustration was less about the attack than its reach: "The challenge is that, without knowing who the bad actors are targeting, it's difficult to reach everyone who might be at risk."
Alex Engler, a former White House official now heading the Penn Center on Media, Technology, and Democracy, was among the confirmed recipients. He told Reuters he received one of the emails, but after checking with industry colleagues discovered that the sender was an impersonator.
The February Anthropic episode fits the same pattern with an even sharper hook. The subject line, "Request for Feedback on Military Integration of Claude," invoked exactly the debate the target was likely following. Proofpoint did not name the impersonated employee or the analyst.
Why the fake login page actually worked
The technical core of the campaign is the part that should worry every organisation running Microsoft 365.
The landing page was built on Frameless BitB, an open-source adversary-in-the-middle kit. Rather than presenting a static imitation of a Microsoft sign-in screen, it draws a fake browser window inside the legitimate page, so the sign-in prompt appears to be a pop-up layered over real content. That presentation choice matters for human factors: victims are conditioned to distrust a stranger's site but to trust a prompt that looks like it belongs to the application they already opened.
Underneath, the kit operates as a reverse proxy. It forwards the victim's credentials to Microsoft as they are typed, in real time. Because the authentication genuinely occurs, the password is accepted, the multifactor code is validated, and conditional access policies evaluate the real session — every control passes. The attacker does not defeat MFA. MFA does exactly what it is supposed to do, and the attacker walks away with the resulting session cookies instead.
Proofpoint reports that TA419 extended the off-the-shelf kit with its own module tracking how far each victim had progressed through the login flow. That module also ticks the "Keep me signed in" box automatically, extending the life of the stolen session, and enters one-time codes the instant they are accepted. The customisation suggests an operator who understood that the value of a session token is measured in how long it stays valid, not in whether the login page looked convincing.
The distinction between stealing a password and stealing a session is the difference between an incident and a breach. A password can be reset; a stolen Microsoft 365 session cookie may grant mail, files, SharePoint and chat without a second factor. Proofpoint's recommendation follows directly: adopt phishing-resistant sign-in such as passkeys, which bind the credential to the legitimate device and cannot be replayed by a proxy.
Infrastructure borrowed from institutions, not criminals
The impersonations extended past individuals into organisations. Proofpoint found that the attackers registered web addresses imitating the Heritage Foundation, Japan's defence minister Shinjiro Koizumi, and the Japan–Taiwan Exchange Association. Each registration supplies borrowed authority to the corresponding email: a message appearing to come from a Washington think tank or a Tokyo official does not need to persuade on its own merits.
The geographic pattern is consistent with Proofpoint's characterisation of TA419 as a group with "a nexus to the U.S. and Japan," whose interests run to "defense, national security, energy, international relations, and foreign policy targets." Proofpoint reads the AI targeting not as a change of subject but as an extension of existing remit — the policy layer surrounding artificial intelligence sits precisely where those interests overlap.
That reading sits within a documented history. A House committee said Chinese state-linked actors used comparable tactics in 2025, impersonating Congressman John Moolenaar. Nextgov/FCW reported in January that a suspected Chinese operation approached a former senior State Department official with an offer to pay for research on US policy toward Venezuela. The International Consortium of Investigative Journalists received suspicious consulting offers after publishing on transnational repression. On Wednesday, MI5 accused the China General Technology Research Institute of funding academic work to improve Chinese intelligence capabilities, with more than 100 UK-based academics contributing, many apparently unaware of the institute's intelligence ties.
Proofpoint expects the campaign to continue, warning that the group "will likely continue targeting think tanks and policy experts working on technologies, and in geographies, of particular interest to the Chinese government" and will "likely also continue spoofing the identities of real subject-matter experts." It does not say how many people were targeted, whether any account was successfully compromised, or whether any information was obtained.
Conclusion
TA419 is a reminder that the hardest part of the current AI competition happens before any code runs. The most consequential capabilities under negotiation — export controls, distillation limits, military integration — are argued inside small circles of policy professionals, and those circles communicate over email, in ordinary language, about topics they care about. An adversary who can appear in that traffic as a credible colleague does not need a zero-day.
There are no patch notes for this. TA419 exploited no software vulnerability; the Frameless BitB kit is openly available and legitimately documented. The failure mode is institutional: professional networks that assume correspondence from a known name arrives from that person, and authentication systems that confirm identity without confirming the session's origin.
The defences are correspondingly unglamorous. Passkeys, which make the proxy attack pointless. Independent-channel verification before acting on an unexpected request, which is exactly how Parker learned about the impersonation and exactly how Engler uncovered it. And treating unsolicited outreach from senior figures as a signal to slow down rather than a signal of recognition.
As Proofpoint has it, humans remain the best line of defence. The uncomfortable corollary is that the humans being targeted are precisely those with the strongest professional incentives to reply quickly and generously to an unexpected invitation from someone they respect.
Images

An illustrative graphic depicting email phishing and credential theft. Wikimedia Commons, CC0.

The north side of the White House in Washington, D.C., from an albumen print dated circa 1880-1900 in the Rijksmuseum Amsterdam collection. An archival photograph, shown for context: Lynne Parker served in the White House Office of Science and Technology Policy in a modern era, not this one. Wikimedia Commons, CC0.
References
- Proofpoint research as reported by Infosecurity Magazine, "China-Linked Hackers Impersonate AI Experts to Target US Policy Insiders", 1 October 2026.
- Nextgov/FCW, "China-linked hackers posed as former US officials, Anthropic employee to target AI experts", 1 October 2026.
- Al Jazeera, "Chinese hackers impersonated AI experts to target US policy minds", 1 October 2026.