Back to News
T

TA419 AI-policy impersonation campaign

News Oct 1, 2026

Proofpoint disclosed a July phishing campaign that impersonated former US technology officials to approach AI-policy experts.

2 sources attached

What happened lately

TA419 AI-policy impersonation campaign timeline

A newly disclosed campaign

Proofpoint disclosed on October 1 that a group it tracks as TA419 approached US AI-policy experts in July while impersonating former government technology officials. The company says the messages proposed a fictitious policy collaboration and, after a recipient replied, directed the target to a fake OneDrive sign-in page intended to capture credentials. The July activity is newly reported, not a claim that an intrusion began on October 1.

Attribution and outcome

Proofpoint describes TA419 as China-aligned. That is the security company’s attribution, not an independently established finding about government direction. Reuters identified former White House official and University of Pennsylvania researcher Alex Engler as one target who recognized the impersonation. The reviewed accounts describe a credential-theft attempt; they do not establish that the attackers obtained a target’s credentials or accessed their email.