AI Governance Institute
← News
Enforcement2026-10-02

Chinese Espionage Group Spoofed Anthropic Exec to Steal AI Policy Credentials

What happened

Proofpoint attributed a sustained 2026 phishing campaign to TA419, a China-aligned espionage group, in findings reported by The Register. Attackers impersonated a senior Anthropic employee and former White House Office of Science and Technology Policy officials. Their targets were AI policy experts at universities, think tanks, and law firms. Lures included fake invitations to AI policy advisory committees and references to Senate foreign relations committee reports on AI export controls. Once targets clicked through, attackers captured their Microsoft 365 usernames and passwords using a technique that intercepts login traffic in real time, built on publicly available phishing toolkits. Proofpoint recommends phishing-resistant credentials such as passkeys. Passkeys are tied to the specific website being accessed, so they cannot be stolen and replayed on a fake site.

Why it matters

  • ·AI policy teams, legal counsel, and government affairs staff are now active espionage targets. Organizations with personnel engaged in AI regulatory work, export control proceedings, or government advisory roles face elevated credential-theft risk that standard phishing training alone cannot address.
  • ·The attack method intercepts credentials even when targets believe they are on a legitimate login page. Standard multi-factor authentication using one-time codes does not stop this technique. Compliance programs that treat password-plus-code as sufficient protection for high-value accounts must reassess that assumption.
  • ·The use of a named Anthropic executive's identity as a lure adds a vendor impersonation dimension. Employees receiving outreach from an AI vendor's leadership on policy or regulatory topics need clear escalation paths. They should verify authenticity before engaging or sharing credentials.

Governance controls affected

What to do now

  • ☐Identify all staff who participate in AI policy, regulatory, or government advisory work and confirm their accounts use phishing-resistant login methods, such as passkeys or hardware security keys, rather than one-time codes that can be intercepted.
  • ☐Brief government affairs, legal, and policy teams on this campaign: tell them to treat any unsolicited invitation to an AI policy committee or advisory group as a potential phishing attempt and to verify directly with the named sender through a known contact channel before clicking any link.
  • ☐Review whether your organization has an escalation path for staff who receive suspicious outreach appearing to come from an AI vendor executive or government official, and confirm that path is documented and tested.
  • ☐Ask your IT or security team whether login protection for email and collaboration tools can block credential-interception attacks, not just password guessing, and get a written answer you can retain for audit purposes.
  • ☐If your organization holds non-public information about AI export controls, procurement decisions, or regulatory strategy, treat that information as a target and confirm access to it is limited to accounts with the strongest available login protection.

What to watch next

Proofpoint's attribution of this campaign to TA419 signals that AI policy and export control communities will remain espionage targets as legislative and regulatory activity around AI intensifies. Organizations should monitor whether government agencies issue formal advisories extending this threat picture, particularly as export control debates referenced in the lures remain active. The credential-interception technique used here has already appeared in financially motivated campaigns. Compliance teams should watch for guidance from identity standards bodies on minimum acceptable authentication methods for high-risk roles. The broader pattern of AI-themed social engineering includes deepfake and impersonation attacks flagged in 41% of CISOs Suffered Deepfake Voice Attacks and the Voice AI PhaaS platform harvesting corporate credentials. These trends indicate that identity verification controls need reassessment as a coordinated program, not a series of one-off fixes.