An invitation to advise on US artificial intelligence policy looked like ordinary professional outreach. In a campaign that began July 8, the senders posed as former White House technology official Lynne Edwards Parker and economist Heidi Crebo-Rediker, according to a Proofpoint investigation published October 1. Recipients who replied were directed toward a counterfeit cloud sign-in flow designed to capture access to their Microsoft accounts.

Proofpoint tracks the suspected operator as TA419 and assesses it as China-aligned and motivated by espionage. That attribution and the proposed intelligence objective are the company's assessments, not a finding independently established by BIG CHANGE. The public report documents attempted credential theft; it does not establish that a target's account was compromised or that emails were taken.

The big change

  • What changed: Proofpoint disclosed targeted July phishing campaigns that used familiar AI policy invitations and impersonated public figures before sending recipients to a counterfeit Microsoft sign-in flow.
  • Why it matters: A plausible first email can make a later document link seem routine. The sought asset was access to policy experts' cloud accounts, not an AI model or a new exploit against one.
  • What to watch: Whether affected organizations confirm account compromise, and whether they adopt independent invitation checks and phishing-resistant authentication. The report alone cannot establish either outcome.

The invitation came before the login page

Proofpoint says the first messages offered a place on a fictitious AI policy advisory committee or a chance to contribute to a supposed Senate Foreign Relations Committee report on AI export controls and supply chains. They did not immediately present a login form. After a reply, a shortened link purported to provide details and ultimately led to a fake OneDrive sign-in page.

The sequence matters because a recipient was asked to make a professional judgment before a security one: is this a real colleague and a credible invitation? The public names were part of the disguise. Parker and Crebo-Rediker were impersonated, not identified as participants in the campaign.

Reuters independently reached Alex Engler, who heads the Penn Center on Media, Technology, and Democracy. Engler said he received an email that appeared to be from Parker inviting him into an AI policy project. He checked with others in the field and recognized the sender as an impostor. Reuters reported that Parker knew of two people who received messages purporting to be from her in early July. Proofpoint told Reuters the observed targeting involved fewer than 10 people at a handful of organizations. This independently confirms one suspicious invitation and adds a bounded account of the campaign's reach; it does not verify Proofpoint's technical reconstruction or attribution.

Why a familiar sign-in screen was part of the trap

Proofpoint's technical analysis says the link passed through redirects and a fake OneDrive loading page into an adversary-in-the-middle sign-in flow. The researchers say the page relayed a Microsoft login in real time and could capture a session after password and conventional multifactor steps. That is the mechanism Proofpoint observed; the report does not say how many recipients entered credentials or whether a session was used.

Proofpoint says it has seen related targeting of US and Japanese think tanks, defense contractors, universities and law firms since at least April 2025. It also describes a February 2026 message impersonating an Anthropic employee to approach a US think-tank AI policy analyst. These dates precede the October disclosure. They should not be read as a fresh October wave or proof that every target was breached.

A check that fits the point of attack

For an unsolicited committee invitation or shared document, the practical check is to contact the purported sender through a known channel before following the new link. That is also Proofpoint's recommendation. Engler's account illustrates the value of checking the sender, though Reuters did not report a full technical account of his message or any account breach.

For organizations, CISA recommends phishing-resistant authentication, including FIDO/WebAuthn, because it binds a sign-in to the genuine site and resists a login initiated through a fraudulent page. This does not replace verification of unexpected requests or prove that a particular organization is protected. It addresses the sign-in relay that Proofpoint describes more directly than a code a user can enter into a lookalike page.

The case is evidence that policy relationships themselves can be used as a route toward account access. Proofpoint's report and Reuters' recipient interview establish an attempted approach and a warning about its method. They do not establish who ultimately controlled the accounts, what information was obtained, or the campaign's final effect on US AI policy.

Sources & further reading