ai-compliancetrade-pressNewsThe Broadside1 min read

Hackers impersonate ex-officials, Anthropic staffer to phish AI experts

The attackers borrowed real reputations as phishing infrastructure, and Proofpoint can't confirm whether any Microsoft accounts fell.


TL;DR

Proofpoint tied a China-aligned group, TA419, to phishing that impersonated former White House AI official Lynne Parker, former State Department chief economist Heidi Crebo-Rediker, and an unnamed senior Anthropic employee. Starting July 8, the attackers invited think tank, university, and law firm researchers to advise on AI policy and export controls, then steered replies to a fake OneDrive page to steal Microsoft credentials. Proofpoint gives no target count and can't confirm any account was compromised.

Proofpoint's Thursday report moves the China-linked collection playbook from the models themselves to the people who shape what happens to them. A group tracked as TA419 impersonated Lynne Parker, a former White House Office of Science and Technology Policy official who ran the National AI Initiative Office, and Heidi Crebo-Rediker, the State Department's first chief economist. From July 8, targets inside think tanks, universities, and law firms received invitations to join a fictitious AI Policy Advisory Committee or contribute to a purported Senate Foreign Relations Committee report on AI export controls and supply chains. Engage, and the next message pointed to a fake OneDrive page built to harvest Microsoft credentials.

Nobody is calling this a breach yet. Proofpoint doesn't say how many people were targeted and can't confirm whether any account was compromised. Parker found out on July 9 when two recipients checked with her through separate channels. That gap is the operational point: the campaign weaponized reputations so that real outreach and real phishing look alike.

The pattern echoes a February message impersonating a senior Anthropic employee under the subject line "Request for Feedback on Military Integration of Claude." It also sits beside September's joint CISA advisory on knowledge distillation, issued with the NSA and FBI, which warned about model extraction. This campaign is the quieter counterpart: it doesn't need to steal weights when it can steal drafts, contacts, and private positioning on export controls and military use.

For the practitioner in that orbit, the Monday move is unglamorous. Verify unexpected advisory invitations out of band, and treat any OneDrive login prompt reached from a cold email as hostile until the sender confirms identity through a channel you initiate.


Published ·Deep Fathom