Back to Now
TA419 AI-policy impersonation campaign debate Developing

Proofpoint says TA419 impersonated ex-US officials to target AI-policy experts

A newly disclosed phishing campaign used fake policy invitations and a counterfeit OneDrive login to approach US AI-policy experts.

Why now Proofpoint's October 1 investigation and Reuters reporting reveal a July campaign aimed at people shaping AI policy, while the outcome remains unconfirmed.

A policy invitation as bait

Proofpoint disclosed on October 1 that a group it tracks as TA419 targeted US AI-policy specialists during July. According to its investigation, the operators impersonated former government technology officials, including former White House official Lynne Parker, and proposed a fictitious collaboration on AI policy. When a recipient replied, the attackers directed that person toward a counterfeit OneDrive sign-in page designed to collect credentials. The disclosure concerns activity Proofpoint observed months earlier; it does not mean a new intrusion took place on October 1.

Reuters identified Alex Engler, a former White House official now at the University of Pennsylvania, as one of the people approached. He recognized the impersonation, Reuters reported. The outlet said Proofpoint observed fewer than 10 targets. Those details describe a focused attempt against people involved in AI policy, not a broad compromise of universities or government systems.

What remains uncertain

Proofpoint calls TA419 China-aligned, which is its attribution based on its research rather than a confirmed finding of government direction. It also describes a separate February impersonation of an Anthropic employee by the same tracked group. The available reporting does not establish that any target entered credentials into the fake page or that attackers accessed email accounts. The verified event is the phishing campaign and its October 1 disclosure; the campaign’s ultimate success remains unconfirmed.