Proofpoint reports impersonation campaign targeting AI policy experts
Cybersecurity firm Proofpoint said a group it tracks as TA419 impersonated former U.S. officials and an Anthropic employee in campaigns aimed at stealing login credentials from people working on artificial intelligence policy. The messages used invitations to take part in purported policy projects before directing recipients to credential-harvesting pages or malicious files, according to the firm’s findings. The targets included experts at think tanks, universities and law firms who work on issues such as AI regulation, export controls and national strategy. Proofpoint said the activity was part of a broader pattern of attempts to steal passwords from people at U.S. and Japanese organizations that it has tracked since at least 2025. In messages sent beginning July 8, attackers posed as Lynne Parker, a former senior White House technology official, and Heidi Crebo-Rediker, a former State Department economist, Proofpoint reported. The emails invited recipients to join a fictitious AI policy committee or contribute to a purported report on AI export controls and supply chains.