A cybersecurity analysis published Oct. 1 attributed phishing campaigns that began July 8, 2026, to TA419. The lures impersonated former U.S. officials Lynne Parker and Heidi Crebo-Rediker to approach AI policy researchers, then steered respondents toward a fake OneDrive sign-in.

A July campaign targeted AI policy experts

The lures approached researchers at U.S. think tanks, universities and law firms. One invitation proposed joining a fictitious AI Policy Advisory Committee; another sought contributions to a purported Senate Committee on Foreign Relations report about AI export controls and supply chains.

The cybersecurity analysis characterized TA419 as China-aligned and espionage-motivated. It assessed that the activity likely sought insight into U.S. AI policy and regulatory developments.

From a professional invitation to a fake sign-in

After a recipient replied, a follow-up message included a shortened link. Redirects led to a fake OneDrive sign-in page targeting Microsoft 365 and Microsoft Entra ID.

The reported flow used adversary-in-the-middle (AitM) phishing: a deceptive page relays the sign-in process to capture authentication details. A customized Browser-in-the-Browser (BitB) overlay—a simulated browser window displayed inside a webpage—made the sign-in appear more convincing. The flow was designed to capture passwords, multi-factor authentication (MFA) codes and session cookies.

No successful account compromise or information acquisition was reported.

Parker said recipients contacted her on July 9

Parker said two recipients contacted her separately on July 9 to ask whether she had sent the messages. She told them the emails were fraudulent and alerted colleagues.

A separate February campaign impersonated an Anthropic employee

In February 2026, a separate campaign impersonated an unnamed senior Anthropic employee in an email to an AI policy analyst at a U.S. think tank. The message sought feedback on the military integration of Claude. The number of people targeted across the campaigns was not reported.