The news
In a report published Oct. 1, 2026, Proofpoint said a China-aligned, espionage-motivated group it tracks as TA419 ran phishing campaigns that impersonated an Anthropic employee and AI policy figures to steal Microsoft 365 logins.
The Anthropic-related campaign came first. In February 2026, Proofpoint says, the group posed as a senior Anthropic employee to contact an AI policy analyst at a US think tank. The subject line was "Request for Feedback on Military Integration of Claude." The employee is not named. Anthropic was not the target; its employee's identity was used as bait.
The larger wave began July 8, 2026. TA419 impersonated Lynne Edwards Parker, former Principal Deputy Director of the White House Office of Science and Technology Policy (OSTP), and then economist and foreign policy expert Heidi Crebo-Rediker. Targets were AI experts at US think tanks, universities and legal-sector organizations.
The lures invited recipients to join a fictitious "AI Policy Advisory Committee" or to contribute to a Senate Committee on Foreign Relations report on AI export controls and supply chains. The first email was benign. If a target replied, the group sent a shortened link that passed through a Cloudflare Turnstile check and a fake OneDrive screen before reaching a credential-phishing page.
Technically, the kit targets Microsoft 365 and Entra ID, Microsoft's identity service. Proofpoint says it is built on the open-source Frameless BitB (Browser-in-the-Browser) toolkit with an Evilginx phishlet, plus a custom module that relays the genuine Microsoft sign-in. This is called adversary-in-the-middle phishing. The attacker captures session cookies, the tokens that keep a user logged in, even when passwords, multi-factor authentication (MFA) and conditional access checks succeed.
Proofpoint also found domains impersonating the Japan-Taiwan Exchange Association, The Heritage Foundation and the website of Japanese Defense Minister Shinjirō Koizumi. It says TA419 activity against US and Japan targets goes back to at least April 2025 and had not been publicly reported. The Register, which independently covered the findings, says the group uses "dozens" of phishing and spoofed-sender domains. Proofpoint did not disclose recipient counts, victims or success rates, so it is unknown whether any account was compromised. No Anthropic, US government or Chinese government comment appeared in the sources reviewed.
The numbers
- Anthropic-spoof campaign
- February 2026
- Main impersonation wave began
- July 8, 2026
- TA419 activity observed since
- At least April 2025
- Phishing and spoofed-sender domains (The Register)
- "Dozens"
Why CEOs should care
Your name and title can be used against other people. Attackers borrowed a real Anthropic employee's identity to reach an outside analyst. Executives, especially at AI firms and their advisers, should assume spoofing is possible and tell partners, researchers and policymakers how legitimate outreach will arrive.
CISOs should check where Microsoft 365 tenants still rely on passwords plus one-time codes. Proofpoint says this relay captures session cookies even when MFA succeeds, and recommends phishing-resistant, origin-bound authentication such as passkeys. Ask your identity team which user groups, such as policy, legal and executive staff, can move first, and what monitoring exists for stolen sessions.
Firms that advise on, lobby on or sell into AI policy circles should treat unsolicited committee invitations or requests for feedback on reports as possible pretexts. Proofpoint advises confirming unexpected subject-matter outreach through a separate channel. Boards can ask whether staff have a simple, no-blame route to report suspicious invitations.
The bigger picture
The report lands amid other US-China tensions around AI. On July 22, 2026, White House OSTP director Michael Kratsios alleged on X that China's Moonshot AI distilled Anthropic's Fable model, according to CyberScoop. Distillation means training a model on another model's outputs. In April, House Homeland Security and China Select Committee leaders opened a probe into what they called adversarial distillation. CyberScoop also cites an earlier Anthropic accusation against Alibaba involving 25,000 fraudulent accounts and 28.8 million Claude interactions over six weeks.
The Register notes the February lure came as US military officials pressed Anthropic over Claude's safeguards. That the attackers chose AI policy as a theme suggests how closely export controls, safeguards and defense use are watched. Attribution here rests on Proofpoint's assessment alone, and The Register's headline says "exec" while Proofpoint says senior employee.
What’s next
Proofpoint expects TA419 to keep targeting think tanks and policy experts and to keep spoofing real people, which is a forecast, not a finding. Watch for comment from Anthropic or the US government, any victim disclosures, and whether Microsoft or other vendors add defenses against session-relay kits. Also watch whether congressional probes into Chinese AI activity cite this campaign.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error
Companies in this story








