Urgent.News

What's breaking now, across thousands of outlets.

Tech

Suspected Chinese spies spoofed an Anthropic exec, ex-White House official in AI phishing

Your invite to a fake AI policy advisory committee has strings attached

Suspected Chinese spies spoofed an Anthropic exec, ex-White House official in AI phishing

A suspected Chinese espionage group impersonated high-ranking AI policy figures, including a former White House official and an Anthropic executive, in a phishing campaign targeting American AI experts. The attacks primarily took place in July 2026, according to security researchers at Proofpoint. The group, known as TA419, targeted AI policy experts at universities, think tanks, and law firms.

The phishing emails, sent from July 8 onward, impersonated Lynne Edwards Parker and Heidi Crebo-Rediker, inviting their targets to join a fake AI policy advisory committee or contribute to a Senate report on AI export controls. Once the victims responded, the attackers redirected them to a credential phishing page that stole their cloud account login information.

The first-stage domains used in these campaigns were driftshare.co and globalfileshareplatform.com. The attackers also impersonated organizations like the Japan-Taiwan Exchange Association, The Heritage Foundation, and Japan's Minister of Defense to further deceive their targets. Experts advise organizations affected by TA419 activity to implement phishing-resistant, origin-bound authentication methods such as passkeys to better protect against these types of attacks.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Tech

I tested 500 emails against HIBP. My validator found a major flaw.

I tested 500 emails against HIBP. My validator found a major flaw. api, #security, #python, #webdev On September 30, 2026, at 17:08 UTC, I sent test@gmail.com to the email validator I had just shipped…

  • Reporter's validator tested 500 emails
  • Found major flaw in breachcheck
  • Returned null istrustedidentity

More from Thursday 1 October →