# TA419 impersonates AI policy figures and an Anthropic employee in credential phishing, Proofpoint reports

> Proofpoint reports that China-aligned TA419 phished AI policy experts in July 2026 with a fake advisory committee and a browser-in-the-browser page that relays MFA codes.

FireAI Security & Research Team (HisnLabs) · Published 2026-10-03
Canonical: https://hisnlabs.com/en/news/ta419-impersonates-ai-policy-figures-credential-phishing-bitb

Proofpoint reports that TA419, a China-aligned espionage actor, ran credential phishing campaigns in July 2026 in which it impersonated prominent economists and AI policymakers to target AI experts at US think tanks, universities and legal sector organisations [[1]](https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy). Help Net Security summarised the findings on 2 October 2026 [[2]](https://www.helpnetsecurity.com/2026/10/02/china-aligned-ta419-phishing-ai-policy-experts/). The campaign is relevant beyond its targets because the technique, a fake login window that relays passwords and MFA codes, works against anyone who signs in to a Microsoft account.

## Background

Credential phishing sends a victim to a page that imitates a sign-in screen. A browser-in-the-browser attack draws a fake browser window inside a web page, including a convincing address bar, so that the sign-in window appears to come from the real service. Proofpoint names the open-source tool used here as Frameless BitB [[1]](https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy) [[2]](https://www.helpnetsecurity.com/2026/10/02/china-aligned-ta419-phishing-ai-policy-experts/).

## Findings

Proofpoint names the impersonated people as Lynne Edwards Parker, a former Principal Deputy Director of the White House Office of Science and Technology Policy, and Heidi Crebo-Rediker, an economist and foreign policy expert [[1]](https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy). In an earlier campaign in February 2026, the actor posed as a senior Anthropic employee [[1]](https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy) [[2]](https://www.helpnetsecurity.com/2026/10/02/china-aligned-ta419-phishing-ai-policy-experts/).

Help Net Security reports that the first messages were benign invitations to join a fictitious AI Policy Advisory Committee or to contribute to a Senate Committee report on AI export controls, and that follow-up emails to respondents contained shortened URLs leading to credential harvesting pages [[2]](https://www.helpnetsecurity.com/2026/10/02/china-aligned-ta419-phishing-ai-policy-experts/). Proofpoint describes multi-stage redirects that end in pages capturing credentials and MFA codes through adversary-in-the-middle attacks on Microsoft 365 [[1]](https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy).

According to Help Net Security, domains controlled by TA419 hosted Cloudflare Turnstile checks and then redirected to fake OneDrive phishing pages, which used Frameless BitB to capture credentials [[2]](https://www.helpnetsecurity.com/2026/10/02/china-aligned-ta419-phishing-ai-policy-experts/). It quotes Proofpoint analyst Mark Kelly as stating that credentials entered in that window are relayed to Microsoft's servers, so the password, the MFA code and conditional access checks would all go through [[2]](https://www.helpnetsecurity.com/2026/10/02/china-aligned-ta419-phishing-ai-policy-experts/).

Proofpoint assesses that the activity likely supports wider Chinese intelligence objectives and that TA419 will likely continue targeting think tanks and policy experts working on technologies, and in geographies, of particular interest to the Chinese government [[1]](https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy) [[2]](https://www.helpnetsecurity.com/2026/10/02/china-aligned-ta419-phishing-ai-policy-experts/).

> FireAI, the on-device firewall for macOS developed by HisnLabs, can check connections against public lists of phishing sites when the optional threat lists are turned on. A 17-day trial is available. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Implications for Mac users

The sources describe a targeted campaign against a specific professional group, and they do not report attacks on the general public [[1]](https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy). The method is not specific to an operating system: the fake window runs inside a web page, so it can appear in any browser on a Mac. The reported use of the names of a government official and of an AI company employee shows that a message can look credible because of who it claims to come from.

## Recommendations

1. Verify an unsolicited message about a committee, report or document through a separate channel before clicking, as Proofpoint advises [[1]](https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy).
2. Use phishing-resistant authentication such as passkeys, which Proofpoint recommends for organisations [[1]](https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy).
3. Be wary of shortened links in a follow-up message from a person met only by email.
4. Open the document service by typing its address or using a saved bookmark, instead of following a link to sign in.
5. If a password or an MFA code was entered on an unexpected page, change the password, revoke active sessions and report it to the organisation.

## Relevance to FireAI

FireAI is a firewall for one Mac. When the optional [threat lists](https://hisnlabs.com/en/docs/threat-intelligence-feeds) are turned on, FireAI downloads public lists, which include Phishing Army and OpenPhish, once a day and can block a match that a list confirms; the traffic itself is never sent to the lists. It also reads the website name that an encrypted connection announces before encryption, as described in [deep inspection without decrypting](https://hisnlabs.com/en/docs/protocol-inspection-without-decryption).

FireAI does not detect a phishing page that is not on a list, including a new domain used by a campaign like this one. It does not read the inside of an encrypted connection, does not see a fake window drawn within a page, and does not read email or judge whether a message is genuine. It cannot stop a user from typing a password into a page that is not blocked, and it does not replace passkeys or an MFA method that resists phishing.

> A phishing page is reached through an ordinary connection. FireAI asks before an app contacts a destination it has no rule for, and its optional threat lists can block a confirmed phishing address. Try it free for 17 days. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Limitations

The campaign description comes from Proofpoint's research and Help Net Security's summary, and the sources do not state how many people were targeted or whether any credential was captured [[1]](https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy) [[2]](https://www.helpnetsecurity.com/2026/10/02/china-aligned-ta419-phishing-ai-policy-experts/). The attribution to China-aligned interests is Proofpoint's assessment. The sources do not say whether the named people or the Anthropic employee were aware of the impersonation.

Try [FireAI, by HisnLabs](https://hisnlabs.com/en/download) free for 17 days.

## Sources

- [Proofpoint Threat Insight: Hallucinating credibility, China-aligned TA419 impersonates its way into US AI policy](https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy)
- [Help Net Security, 2 October 2026: Chinese spies impersonate White House, Anthropic figures to phish AI policy experts](https://www.helpnetsecurity.com/2026/10/02/china-aligned-ta419-phishing-ai-policy-experts/)
