“The challenge is that, without knowing who the bad actors are targeting, it’s difficult to reach everyone who might be at risk,” Lynne Parker told reporters after learning that her name was used in a phishing campaign aimed at artificial intelligence policy experts.
Proofpoint's findings: targeted phishing aimed at AI policy researchers
Cybersecurity company Proofpoint reported a series of phishing campaigns that impersonated prominent figures to approach U.S. AI policy researchers at think tanks, universities and law firms. According to Proofpoint, the initial messages invited recipients to advise on AI policy or contribute to work on export controls and supply chains; when targets engaged, the attackers followed up with links intended to steal Microsoft login credentials via a fake OneDrive page.
Proofpoint connected the activity to a group it tracks as TA419, calling it a “China-aligned outfit supporting Beijing’s intelligence interests.” The company’s report did not specify how many people were targeted, whether any accounts were compromised, or whether the attackers obtained information.
TA419's impersonations: Parker, Crebo-Rediker, and an Anthropic employee
The campaigns impersonated named U.S. figures and a private-sector employee. Proofpoint identified messages that posed as Lynne Parker — described in the report as a former principal deputy director of the White House Office of Science and Technology Policy whose White House roles included assistant director for AI and founding director of the National AI Initiative Office — and Heidi Crebo-Rediker, who “served as the State Department’s first chief economist,” is now a Council on Foreign Relations senior fellow, and previously worked as the Senate Foreign Relations Committee’s chief of international finance and economics.
Proofpoint also said the group used a similar approach in February, impersonating a senior Anthropic employee in an email to an AI policy analyst at a U.S. think tank. The February message used the subject line “Request for Feedback on Military Integration of Claude,” invoking debate over military use of Anthropic’s models; the report did not name the Anthropic employee.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildTactics: fake OneDrive pages and spoofed organizational domains
Proofpoint described a consistent playbook: open with an apparently routine professional request — invitations to join a fictitious “AI Policy Advisory Committee” or to contribute to a purported Senate Foreign Relations Committee report on AI export controls — then, once the target replies, deliver a credential-harvesting link. The company said attackers directed targets to a fake OneDrive page to attempt Microsoft account theft.
To increase believability, the attackers registered web addresses impersonating organizations and officials, including the Heritage Foundation, Japan’s defense minister Shinjiro Koizumi, and the Japan–Taiwan Exchange Association. Proofpoint noted the group’s historical interest in “defense, national security, energy, international relations, and foreign policy targets, predominantly with a nexus to the U.S. and Japan,” and said the targeting of AI policy experts is an extension of that remit.
Reactions: individuals, companies, and governments named in the campaign
Lynne Parker confirmed she learned of the impersonation on July 9, when two recipients contacted her through separate channels to ask whether she had sent the emails. “It is personally troubling to see the trust and relationships I’ve built over my career exploited to deceive others,” she said, and added that she alerted colleagues after determining the messages were fraudulent.
Heidi Crebo-Rediker and Anthropic did not respond to requests for comment, Proofpoint reported. The story’s reporters also contacted China’s embassy in Washington, D.C.; the report noted that Chinese officials have routinely denied allegations of state-backed hacking and espionage.
Outside observers quoted by the report underscored the human element of the threat. Don Styer, identified as a former Navy Supply Corps officer and executive vice president for federal services at Consulting Solutions, said, “At the end of the day, humans are our best line of defense,” warning that attackers exploit trust through impersonation and routine requests.
What this means for AI policy researchers, think tanks, and AI companies
- AI policy researchers: Private email or cloud accounts can contain discussions, drafts, and contacts relevant to AI development, military use, and export policy; the campaigns show those accounts can be a target for credential theft via tailored professional outreach.
- Think tanks, universities, and law firms: The impersonations — including domains spoofing established organizations and officials — illustrate how readily familiar names and routine outreach can be weaponized. Institutional awareness and rapid reporting channels mattered in this case: Parker learned from direct inquiries and alerted colleagues.
- AI companies and officials involved in Washington debates: The report highlights the growing intersection between industry engagement in policy debates and espionage risk. Proofpoint’s findings sit alongside other recent reporting cited in the same article — including accusations by the NSA and other agencies about large-scale distillation campaigns and a separate MI5 allegation about a Chinese institute’s funding of academic projects — underscoring a broader set of intelligence collection concerns tied to AI.
Proofpoint concluded that the attackers “will likely continue targeting think tanks and policy experts working on technologies, and in geographies, of particular interest to the Chinese government” and “will likely also continue spoofing the identities of real subject-matter experts.” The immediate, concrete detail left on the record is simple: familiar names and routine professional queries were used as the opening gambit, and defenders were left to identify and interrupt the second act — links designed to harvest Microsoft credentials.




