TA419 impersonated an Anthropic employee in a credential-phishing campaign
Proofpoint tracked the China-aligned group TA419 impersonating a senior Anthropic employee in emails targeting US policy experts. The messages asked recipients for feedback on Claude’s military integration and included apparently harmless collaboration proposals.

Key takeaways · 4
- 01
TA419 impersonated a senior Anthropic employee and sought feedback on Claude’s military integration.
- 02
The emails began with collaboration proposals, including an invitation to join an AI Policy Advisory Committee.
- 03
The customized Frameless BitB attack could capture Microsoft 365 passwords, multifactor-authentication codes and session cookies.
- 04
Proofpoint did not identify the specific targets it said were hacked; Alex Engler confirmed receiving an email, not that his account was compromised.
A policy invitation opened the door
The emails presented apparently benign collaboration proposals, including invitations to join an AI Policy Advisory Committee.[3] In one approach, the sender impersonated a senior Anthropic employee and requested feedback on Claude’s military integration.[3] After a recipient replied, the attackers directed them to a fake login page designed to steal credentials.[1] This sequence makes the initial outreach part of the credential-theft attempt, rather than simply an unsolicited request for views. Professionals receiving similar invitations should verify the sender through a separate, trusted channel before following links or sharing account information.
A counterfeit login inside a redirect chain
IT Pro reported that the attackers used a multi-stage URL redirection chain to deliver an adversary-in-the-middle credential-phishing attack.[3] The operation used a customized version of Frameless BitB, an open-source tool that creates a counterfeit browser window inside a webpage.[3] The phishing page placed a fake Microsoft login pop-up over a page made to resemble a OneDrive document-sharing site, then relayed login information to genuine Microsoft infrastructure.[3] The technique could harvest Microsoft 365 passwords, multifactor-authentication codes and session cookies.[3] A familiar-looking sign-in window, therefore, is not by itself proof that a login request is legitimate.
Targets and confirmed details
Al Jazeera reported that TA419 had been operating since April 2025 and targeted policy experts at think tanks, defense contractors, universities and law firms in the United States and Japan.[1] It also reported that the group targeted a slate of US policy experts in July.[1] Proofpoint did not name the specific targets it said had been hacked.[1] Reuters confirmed that at least one target was Alex Engler, a former White House official who leads the Penn Center on Media, Technology, and Democracy; Engler said he received an email and identified it as an impersonation after checking with industry colleagues.[1] Al Jazeera also reported that TA419 impersonated a prominent Anthropic employee in February.[1] Proofpoint expects the group to continue targeting policy experts and impersonating real-world experts.[1]
The campaign shows how a credible policy-themed approach can lead into a credential-theft flow that imitates familiar login experiences. For professionals handling sensitive policy or organizational information, verify unexpected collaboration requests independently and treat sign-in links with care.
Why it matters
Put this to work — one session a day, built for your industry.
Create a free account for a daily session — eight questions and one real-work challenge, on the news that affects your role.
Start freeHow this developed
3 October 2026
TA419 impersonated an Anthropic employee in a credential-phishing campaign
Sources
- Chinese hackers impersonated AI experts to target US policy minds | Cybersecurity News | Al Jazeeraaljazeera.com
- Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles | Proofpoint USproofpoint.com
- Chinese hackers impersonate leading AI figures to harvest credentials | IT Proitpro.com