Security News

Suspected Chinese Spies Used Fake AI Policy Invites to Phish US Experts

The Register · 2 Oct 2026
Key Takeaway Staff who handle sensitive policy, research, or client information should verify unexpected invitations or requests through a separate, trusted channel before clicking links or entering login credentials.

Security researchers at Proofpoint say a suspected Chinese espionage group, tracked as TA419, ran phishing campaigns throughout July targeting AI policy experts at US universities, think tanks, and law firms. The attackers impersonated real public figures, including a former White House Office of Science and Technology Policy official and a senior Anthropic employee, inviting targets to join a fake AI policy advisory committee or contribute to a report on AI export controls.

When victims replied, the attackers sent a shortened link that led to a fake OneDrive page. After passing a security check designed to look legitimate, victims were redirected to a credential-harvesting page that stole their cloud account login details. Researchers note this follows a similar incident in February, where the same group impersonated an Anthropic employee to phish an AI policy analyst using a message about military use of AI.

The campaigns highlight how attackers are using the credibility and topicality of AI policy discussions to lure well-connected professionals into compromising their accounts. Because the phishing relies on impersonating trusted individuals and legitimate-sounding invitations, standard spam filters may not catch it.

Summarised by CISO AI from The Register. We link back to every original so you can read it yourself.