China-linked hackers posed as Anthropic staff to phish U.S. AI policy experts
A group tracked as TA419 ran fake-login pages that could capture passwords and the one-time codes meant to stop them.

Key points
- A China-aligned group called TA419 impersonated prominent economists, AI policymakers and at least one Anthropic employee to phish AI policy specialists at U.S. Think tanks, universities and legal sector firms.
- The attackers used an adversary-in-the-middle fake login page, which sits between the victim and the real Microsoft sign-in and steals both the password and the session cookie.
- Because the fake page relays the real multi-factor code in real time, app-based and SMS codes do not stop it; only phishing-resistant keys do.
- The targeting lines up with Beijing's interest in how Washington is drafting rules for frontier AI models.
- Anyone contacted by a "researcher" asking them to open a document via a Microsoft login should verify through a second channel before clicking.
A China-linked espionage crew is going after the small world of people who help write America's AI rules, and it's doing so by pretending to be their colleagues.
TA419 has been running credential phishing campaigns, meaning emails designed to trick someone into typing their password into a fake login page, against AI policy specialists at U.S. Think tanks, universities and legal sector firms. Researchers detailed the campaigns this week, tracking a cluster of lookalike Microsoft login pages used across the operation.
In at least one case the attackers impersonated an Anthropic employee to approach a specific AI policy expert. Other lures leaned on the names of prominent economists and AI policymakers. The pitch is familiar: a draft paper to review, a panel invitation, a shared document. Targets see what looks like a normal Microsoft sign-in screen and type in their work credentials.
How did the attack actually work?
The fake page wasn't a static copy. It was an adversary-in-the-middle proxy, a server sitting between the victim's browser and the real Microsoft login, forwarding keystrokes to the genuine site and relaying responses back. The victim sees the real multi-factor prompt because the attacker triggers it live.
When the victim enters the six-digit code from their authenticator app, the proxy passes that too. Microsoft issues a valid session cookie, a small file the browser uses to stay logged in, and the attacker grabs it. From that moment the attacker is signed in as the victim, no password needed.
This is why MFA is necessary but no longer sufficient on its own. App codes and SMS codes get relayed. What doesn't get relayed is a hardware security key or a passkey bound to the real Microsoft domain, because the browser won't hand the credential to a lookalike address. That's the control that would have stopped this.
Who is being targeted and why?
The victim pool is narrow and deliberate: people shaping how the U.S. Government will regulate frontier AI models, export controls on chips, and research partnerships with Chinese institutions. For a state intelligence service, a week inside one such person's inbox is worth more than millions of consumer records.
TA419's choice to impersonate an Anthropic staffer is telling. We reported on 17 September that Anthropic's own threat report documented state actors abusing Claude for tasks ranging from automating break-ins to supporting weapons research. The group clearly knows which labs the policy community actually talks to, and which names won't trigger a second thought.
Should you worry?
If you work anywhere near AI policy, treat the next polite email from a "researcher" with a shared document as hostile until proven otherwise. Verify through a known phone number or a Signal message before signing in to anything.
For everyone else, the lesson is smaller but real. The six-digit code from your authenticator app is helpful against opportunistic attackers and useless against a live proxy. If your employer offers hardware keys or passkeys for work accounts, use them. If your bank or email provider offers a passkey, the five minutes to set it up is the cheapest security upgrade available right now.
Attribution to China fits a pattern we've followed closely. On 2 October we reported that a backdoor called Antino was sitting on at least 16 government networks across eight Asian countries, communicating through legitimate Microsoft 365 traffic. TA419's credential-theft approach is different in method but identical in ambition. Expect more operations like this as the rules being drafted in Washington start to bite.



