China Aligned TA419 Targets US AI Experts With Phishing Attacks
A China-linked cyber espionage group called TA419 targeted U.S. artificial intelligence policy experts in phishing campaigns designed to steal Microsoft credentials and session cookies.
FTMQ Security, written by our newsroom0 views

A China-aligned cyber espionage group known as TA419 has targeted artificial intelligence policy experts in the United States with credential phishing campaigns, according to reports from The Hacker News, news.lavx.hu, and gbhackers.com. The espionage group focused on individuals working for U.S. think tanks, universities, and legal sector organizations by deploying Microsoft adversary-in-the-middle phishing attacks. [1][2][3]
The Hacker News reported that the malicious campaigns used reply-triggered adversary-in-the-middle phishing designed to capture Microsoft login credentials and session cookies. In February 2026, the attackers targeted an artificial intelligence policy expert at a U.S. think tank by impersonating a prominent Anthropic employee. The group also impersonated prominent economists and artificial intelligence policymakers during its operations. [1]
According to The Hacker News, the phishing email sent to the think tank expert used the subject line Request for Feedback on Military Integration of Claude. This form of attack transparently relays authentication processes to a legitimate website, which allows the attackers to hijack active user sessions and collect sensitive credentials. [1][6]
Phishing remains a primary method for gaining initial access to systems, enabling session hijacking, credential theft, malware delivery, or command execution. Strategic cyberwarfare involves targeting information systems for tactical or military purposes, encompassing cyberattacks attributed to state organs and related advanced persistent threat groups in the People's Republic of China. [4][6]
In short
- China-aligned group TA419 targeted U.S. AI policy experts with Microsoft credential phishing.
- The attackers impersonated an Anthropic employee and used the email subject Request for Feedback on Military Integration of Claude.
- The campaign relied on adversary-in-the-middle techniques to capture login credentials and session cookies.
Sources
Every paragraph above points to the numbered items it rests on. Read the originals here.
- [1]China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingThe Hacker News, 17h ago (the report this story comes from)
- [2]China-Linked TA419 Targets U.S. AI Policy Experts With Microsoft Adversary-in-the-Middle Phishingnews.lavx.hu, 12h ago
- [3]China-Linked TA419 Hackers Target US AI Policy Experts With Credential Phishing Attacksgbhackers.com, 2d ago
Background
- [4]Cyberwarfare and China on Wikipedia
- [5]Mohamed Belhocine on Wikipedia
- [6]Phishing on Wikipedia
Our newsroom writes these reports with the help of software, from the 6 sources listed and nothing else, and checks them against those sources. Facts can still be wrong or move on; the originals are the record. Spotted a mistake? Write to daniel@monsterkong.com.
More in Top Stories
- Citrix issues emergency updates for NetScaler zero day vulnerability1h ago
- Suspected ShinyHunters Hacker Detained in Jordan Cooperating With FBI8h ago
- Anthropic requests voice conversation data from Claude users for model training8h ago
- Donald Trump Appoints National Intelligence Director Jay Clayton to Head AI Task Force8h ago
Get the day in one email
Reports like this one, the top news of the last 24 hours, every morning. Free, one email a day; readers can comment under every report.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.

Comments
Loading
Join the conversation
Comments are open to readers of our daily email: the top news of the last 24 hours, every morning, free. Sign up and the comment box opens.
Already on the list? Enter the same address and we will send a sign-in link.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.