China-Aligned Hackers Posed as Anthropic Staff to Phish AI Policy Experts
The subject line was built to be opened: “Request for Feedback on Military Integration of Claude.” In February 2026 it landed in the inbox of an AI policy analyst at a U.S. think tank, apparently from a senior Anthropic employee. It was not from Anthropic. According to a report Proofpoint published on Oct. 1, it came from TA419, a group the security firm calls “a China-aligned and espionage-motivated threat actor.”
The email led to an adversary-in-the-middle credential phishing page, the same trap TA419 has used against think tanks, defense contractors, universities and law firms in the U.S. and Japan since at least April 2025. The Hacker News covered the findings on Oct. 4.
How the TA419 Anthropic phishing lure worked
The timing was the clever part. Proofpoint says the lure referenced the debate over U.S. military use of Claude, which was very live that month: on Feb. 26, Anthropic CEO Dario Amodei published a statement refusing the Department of War’s demand to drop safeguards against mass domestic surveillance and fully autonomous weapons. “These threats do not change our position: we cannot in good conscience accede to their request,” he wrote. For a policy analyst, an Anthropic insider asking for input on exactly that fight is the email you answer.


The campaigns tend to follow a pattern, per The Hacker News: open with a plausible request, and send a link once the target engages. That link runs through URL shorteners and a chain of redirects to a fake OneDrive page, complete with a Cloudflare Turnstile check that makes it look like a real security gate. Then comes what Proofpoint calls a customized “Frameless BitB” kit, a browser-in-the-browser trick that draws a fake login window inside the page.
Behind it sits a proxy, which is what “adversary-in-the-middle” means. Victims type their Microsoft password into what looks like Microsoft, and the attacker relays it to the real service, capturing both the credentials and the session cookie that comes back. A one-time code from an authenticator app does not help here. The attacker simply passes it along.
Who else TA419 pretended to be
Anthropic was one costume among several. In July 2026, Proofpoint says, TA419 impersonated Lynne Parker, a former principal deputy director of the White House Office of Science and Technology Policy, and economist Heidi Crebo-Rediker. Lures invited targets to join an “AI Policy Advisory Committee” or contribute to a Senate Committee on Foreign Relations report on AI export controls. The group has also posed as the Heritage Foundation, the Japan-Taiwan Exchange Association and the official website of Japanese politician Shinjiro Koizumi.
The sender addresses were not convincing spoofs. Proofpoint’s indicator list shows freemail accounts on mail.com and outlook.com in the impersonated people’s names. The credibility came from the subject matter, not the domain.
“This activity likely supports wider Chinese intelligence objectives to better understand ongoing developments within the US AI policy and regulatory landscape,” Proofpoint wrote.
One detail worth noticing: despite the report’s title, “Hallucinating Credibility,” Proofpoint does not say TA419 used AI to write its lures. The hard part was knowing which arguments a think-tank analyst would want to weigh in on. That is research, and humans have been doing it for a long time.
Why Canadian researchers should care
Proofpoint’s report names U.S. and Japanese targets, not Canadian ones. Canada’s own cyber agency has been blunt about the wider pattern, though. The Canadian Centre for Cyber Security’s National Cyber Threat Assessment 2025-2026 calls China’s cyber program “the most sophisticated and active state cyber threat to Canada today” and says it “almost certainly continues to support the PRC’s espionage activities against Canada’s private sector, academia, supply chains, and government-affiliated research and development.” It also notes that members of the Inter-Parliamentary Alliance on China received spear-phishing emails carrying tracking images.
Anyone in Canadian AI policy, at a university, a think tank or a ministry, works on the same files TA419 is mining for: export controls, military AI, model safety. Our read: Ottawa’s AI policy circle is small enough that a fake email from a recognizable name would get read.
What to do if you work in AI policy or academia
- Verify through a second channel. Proofpoint’s advice is to “treat unsolicited subject-matter outreach as a plausible pretext stage” and confirm it “via another independent medium.” Call the person, or message them somewhere you already know is theirs.
- Distrust freemail from institutional names. A senior Anthropic or White House figure writing from mail.com is the tell in this campaign.
- Be suspicious of file-share links that arrive after you reply. A OneDrive page behind a shortened link and a CAPTCHA is the TA419 sequence.
- Switch to passkeys or a hardware key. Proofpoint recommends “phishing-resistant, origin-bound authentication such as passkeys.” The U.S. Cybersecurity and Infrastructure Security Agency calls FIDO/WebAuthn “the only widely available phishing-resistant authentication”, because the key checks which site it is talking to. Our passkeys guide walks through setup.
- If you clicked, revoke sessions as well as resetting your password. A stolen session cookie can outlive a password change until active sessions are signed out.
Proofpoint names two domains in its indicator list, driftshare[.]co and globalfileshareplatform[.]com. Neither sounds like Microsoft. Both sound exactly like a place a busy analyst might go to download a draft about Claude.
Oman Hassan covers cybersecurity and privacy for prompt/power: breaches, exploits, surveillance and the policy that follows them. He assumes the password is "password" until proven otherwise.
Latest from prompt/power
- The Family Safe Word: How to Beat AI Voice-Clone Emergency ScamsOct 7
- Reflection AI’s Beam, Explained: The 501B Open-Weight Model Aimed at ChinaOct 7
- Your SSN or SIN Leaked in a Breach? Do These 8 ThingsOct 7
- Apple’s Oct. 13 Event Rumour, Plus iPhone Duo Pre-Order Dates for CanadaOct 7
- Why Grindr Is Paying US$250M for Calgary PrEP Clinic FreddieOct 7
Leave a Reply