CYBERSECURITYTRACKER
TRACKING
Permanent story citation

AI policy circles targeted in China-linked phishing operation

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 9130

As cited

Copy frozen at (site build).

threat intel

AI policy circles targeted in China-linked phishing operation

A China-aligned group tracked as TA419 launched phishing campaigns against U.S. artificial intelligence policy experts at think tanks, universities, and law firms, impersonating White House officials, economists, and an Anthropic employee. The attacks used adversary-in-the-middle techniques with fake Microsoft OneDrive login pages and the Frameless BitB phishing tool to capture credentials and active sessions. The activity began in July and reflects broader U.S.-China competition over AI development and technology policy.

Why it matters: Policy professionals, researchers, and legal advisors working on AI export controls and national security face credential theft and account compromise; practitioners should alert staff to verify sender identity through direct contact and review phishing indicators published by Proofpoint.

VendorsCloudflareMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary