Skip to main content

TA419 impersonated an Anthropic employee in a credential-phishing campaign

3 OCTOBER 2026·2 MIN READ·3 SOURCES

Proofpoint tracked the China-aligned group TA419 impersonating a senior Anthropic employee in emails targeting US policy experts. The messages asked recipients for feedback on Claude’s military integration and included apparently harmless collaboration proposals.

TA419 impersonated an Anthropic employee in a credential-phishing campaign

Key takeaways · 4

  • 01

    TA419 impersonated a senior Anthropic employee and sought feedback on Claude’s military integration.

  • 02

    The emails began with collaboration proposals, including an invitation to join an AI Policy Advisory Committee.

  • 03

    The customized Frameless BitB attack could capture Microsoft 365 passwords, multifactor-authentication codes and session cookies.

  • 04

    Proofpoint did not identify the specific targets it said were hacked; Alex Engler confirmed receiving an email, not that his account was compromised.

A policy invitation opened the door

The emails presented apparently benign collaboration proposals, including invitations to join an AI Policy Advisory Committee.[3] In one approach, the sender impersonated a senior Anthropic employee and requested feedback on Claude’s military integration.[3] After a recipient replied, the attackers directed them to a fake login page designed to steal credentials.[1] This sequence makes the initial outreach part of the credential-theft attempt, rather than simply an unsolicited request for views. Professionals receiving similar invitations should verify the sender through a separate, trusted channel before following links or sharing account information.

A counterfeit login inside a redirect chain

IT Pro reported that the attackers used a multi-stage URL redirection chain to deliver an adversary-in-the-middle credential-phishing attack.[3] The operation used a customized version of Frameless BitB, an open-source tool that creates a counterfeit browser window inside a webpage.[3] The phishing page placed a fake Microsoft login pop-up over a page made to resemble a OneDrive document-sharing site, then relayed login information to genuine Microsoft infrastructure.[3] The technique could harvest Microsoft 365 passwords, multifactor-authentication codes and session cookies.[3] A familiar-looking sign-in window, therefore, is not by itself proof that a login request is legitimate.

Targets and confirmed details

Al Jazeera reported that TA419 had been operating since April 2025 and targeted policy experts at think tanks, defense contractors, universities and law firms in the United States and Japan.[1] It also reported that the group targeted a slate of US policy experts in July.[1] Proofpoint did not name the specific targets it said had been hacked.[1] Reuters confirmed that at least one target was Alex Engler, a former White House official who leads the Penn Center on Media, Technology, and Democracy; Engler said he received an email and identified it as an impersonation after checking with industry colleagues.[1] Al Jazeera also reported that TA419 impersonated a prominent Anthropic employee in February.[1] Proofpoint expects the group to continue targeting policy experts and impersonating real-world experts.[1]

The campaign shows how a credible policy-themed approach can lead into a credential-theft flow that imitates familiar login experiences. For professionals handling sensitive policy or organizational information, verify unexpected collaboration requests independently and treat sign-in links with care.

Why it matters
Daily session

Put this to work — one session a day, built for your industry.

Create a free account for a daily session — eight questions and one real-work challenge, on the news that affects your role.

Start free

How this developed

  1. 3 October 2026

    TA419 impersonated an Anthropic employee in a credential-phishing campaign

Sources

AI fluency, one session a day, built for your work.