AI Phishing Targets Anthropic Exec and Ex-White House Official
Suspected Chinese state-sponsored actors conducted a phishing campaign targeting individuals in the AI sector. The attackers spoofed an Anthropic executive and a former White House official, inviting targets to a fake AI policy advisory committee. This social engineering attempt aimed to compromise high-value individuals within the AI supply chain. The extent of any successful compromises remains undisclosed.
Severity: High · Category: Supply Chain
Impact: Compromise of individuals in the AI sector, potential data exfiltration.
Source: The Register · Oct 01 2026 · Original source
What Happened
A suspected Chinese espionage group, tracked by Proofpoint as TA419, conducted phishing campaigns impersonating AI policy figures. These campaigns targeted AI policy experts at US universities, think tanks, and law firms. The group spoofed a senior Anthropic employee and a former White House official, Lynne Edwards Parker, as well as economist Heidi Crebo-Rediker, to invite targets to join a fake AI policy advisory committee or contribute to a Senate foreign relations committee report on AI export controls and supply chains. If a target replied, they were sent a shortened URL leading to an attacker-controlled domain designed to steal cloud account login information.
Timeline
- February 2026 — Chinese spies spoofed a senior Anthropic employee to phish an AI policy analyst at a US think tank, using the subject line "Request for Feedback on Military Integration of Claude."
- July 2026 — The bulk of the phishing campaigns occurred, with TA419 impersonating multiple individuals in credential phishing campaigns targeting AI policy experts in the US.
- July 8, 2026 — TA419 began sending phishing emails spoofing Lynne Edwards Parker and Heidi Crebo-Rediker to American AI policy experts.
- October 1, 2026 — Proofpoint published its security alert detailing the espionage attempts and attribution to TA419.
Technical Analysis
The phishing chain employed a multi-stage process. Initial replies from targets received a shortened URL that redirected to an attacker-controlled domain. This page presented a Cloudflare Turnstile check behind a phony OneDrive loading screen before redirecting the victim to an attacker-in-the-middle (AitM) credential phishing page. This page was designed to steal the victim’s cloud account login information. The July 2026 campaigns utilized driftshare[.]co as the first-stage domain and globalfileshareplatform[.]com as the second-stage domain. TA419’s phishing chain specifically targeted Microsoft 365/Entra ID through the first-party OfficeHome application (client_id=4765445b-32c6-49b0-83e6-1d93765276ca). The infrastructure was built on open-source Frameless BitB, which includes a Browser-in-the-Browser (BitB) overlay, an Evilginx phishlet to intercept usernames, passwords, and session cookies for Microsoft 365, and server-side substitution rules to inject the kit into proxied pages. TA419 typically used Cloudflare’s content delivery network to conceal the backend hosting IP address for its domains, and its credential phishing domains were often themed around file sharing sites and cloud services, such as msfile[.]online and onecloudfilesync[.]com. The group also impersonated specific organizations and individuals, including the Japan-Taiwan Exchange Association (tw-koryu[.]org), The Heritage Foundation (heritiages[.]org and heritiage[.]org), and Japanese Minister of Defense Shinjirō Koizumi’s official website (shinjirou[.]info), using dozens of phishing and spoofed-sender domains and phony email addresses.
Impact
The phishing campaigns aimed to compromise AI policy experts at US universities, think tanks, and law firms by stealing their cloud account login information. The targets included high-profile individuals such as a senior Anthropic employee and a former principal deputy director of the White House Office of Science and Technology Policy, Lynne Edwards Parker, as well as prominent economist and foreign policy expert Heidi Crebo-Rediker. The objective was to gain unauthorized access to these individuals' cloud accounts, potentially leading to data exfiltration or further espionage against entities working on technologies of interest to the Chinese government.
Discovery & Response
Proofpoint discovered the espionage attempts and attributed them to the China-aligned group TA419. Proofpoint threat-intelligence analyst Mark Kelly detailed the findings in a report. Threat hunters recommend that organizations within the scope of TA419 activity consider implementing phishing-resistant, origin-bound authentication methods, such as passkeys, to mitigate similar threats.
How Fencio prevents this
The agent trusted a component it had never verified: a package, an extension, a skill, or a server that looked legitimate. When that component changed or was compromised, the agent carried the payload straight into a trusted environment.
Fencio inventories every tool, server, and skill an agent can reach, pins their versions and declared capabilities, and blocks calls when a component starts doing something its manifest never declared, like reading env files or mailing new recipients.