# Chinese espionage group used fake AI policy invites to phish US experts

> In July 2026 a China‑linked group impersonated Anthropic staff and a former White House official in phishing emails aimed at AI policy makers.

Oossa · 2026-10-01 · https://oossa.com/en/chinese-espionage-group-used-fake-ai-policy-invites-to-phish-us-experts

In early July 2026 a suspected Chinese espionage group, tracked as TA419, sent phishing emails that pretended to be from a senior Anthropic employee and a former White House science adviser. The messages asked AI policy experts at US universities, think tanks and law firms to join a bogus AI policy advisory committee or help a Senate report on AI export controls. If a recipient clicked the link, they were taken to a fake OneDrive page that then redirected to a credential‑stealing site.

## How the scam worked

The first link in the chain used the domain driftshare.co, which pointed to a Cloudflare‑protected page. That page showed a Cloudflare Turnstile check behind a fake OneDrive loading screen. After the check, the victim was sent to a second domain, globalfileshareplatform.com, that hosted an attacker‑in‑the‑middle (AitM) page. The page captured Microsoft 365/Entra ID login details using open‑source tools that overlay a browser inside the browser. The group also used other file‑sharing‑style domains such as msfile.online and onecloudfilesync.com to hide its activity.

## What experts recommend

Proofpoint’s analysis suggests organisations likely to be targeted should adopt phishing‑resistant authentication, such as passkeys that are bound to the original login origin. The group’s domains are hosted behind Cloudflare’s content delivery network, making it harder to trace the servers. TA419 has a history of impersonating other organisations, including the Japan‑Taiwan Exchange Association and the Heritage Foundation.

## The facts

- The phishing campaign began on July 8, 2026, according to Proofpoint.
- TA419 spoofed Lynne Edwards Parker, a former White House OSTP deputy director, and economist Heidi Crebo‑Rediker.
- The emails invited recipients to join a fake AI policy advisory committee or contribute to a Senate report on AI export controls.
- The first‑stage domain used was driftshare.co; the second‑stage domain was globalfileshareplatform.com.
- Proofpoint recommends passkeys as a phishing‑resistant authentication method.

## Why it matters

University researchers, think‑tank analysts and law‑firm consultants could have had their Microsoft 365 accounts compromised, giving attackers access to internal communications and documents. For anyone handling sensitive AI policy work, the episode shows that simple email invitations can be a gateway to credential theft, underscoring the need for stronger login protections. It remains unclear how many accounts were actually compromised, but the tactics suggest future attacks will keep targeting policy influencers.

## Sources & references

1. [Suspected Chinese spies spoofed an Anthropic exec, ex-White House official in AI phishing](https://www.theregister.com/security/2026/10/01/suspected-chinese-spies-spoofed-an-anthropic-exec-ex-white-house-official-in-ai-phishing/5300595) – The Register, 2026-10-01

Last updated: 2026-10-01
