TA419 posed as ex-White House official to phish AI policy experts
China-aligned group TA419 sent collaboration invitations in the names of Lynne Parker and Heidi Crebo-Rediker to AI policy specialists at think tanks, universities and law firms. After a reply, targets were routed to a fake Microsoft OneDrive sign-in page in an adversary-in-the-middle attack that captured passwords, MFA approvals and session data. Fewer than 10 people were targeted.
- TA419 wrote as Lynne Parker and Heidi Crebo-Rediker starting July 8
- Phishing mimicked an AI advisory committee and a Senate export-control report
- Fake OneDrive login relayed credentials to real Microsoft infrastructure
- Fewer than 10 AI policy experts at a handful of organizations were targeted
Read next
Security