Skip to the stories
Sunday, 4 October 2026
Saved

Next edition

4:11

Headlines

Cybersecurity

China aligned TA419 group targets US AI policy experts in phishing campaign

A cyber espionage group linked to China has targeted artificial intelligence policy experts in the United States through an adversary-in-the-middle phishing scheme.

FTMQ News, written by our newsroom1 view

Share
Picture: The Hacker News

A China-nexus cyber espionage group named TA419 has targeted artificial intelligence policy experts working at United States think tanks, universities, and legal sector organizations with credential phishing campaigns, The Hacker News and gbhackers.com reported. [1][2]

The Hacker News reported that the group uses reply-triggered adversary-in-the-middle phishing attacks to steal Microsoft credentials and session cookies. The campaigns have impersonated prominent economists, AI policymakers, and an employee of Anthropic to focus on an AI policy expert at a U.S. think tank in February 2026. [1]

According to The Hacker News, one phishing email used the subject line Request for Feedback on Military Integration of Claude. Phishing is a social engineering technique where attackers deceive individuals into giving away sensitive information or relaying authentication to capture credentials. [1][5]

Cyberwarfare in the People's Republic of China involves cyberattacks attributed to state organs and related advanced persistent threat groups. As FTMQ News reported earlier, another suspected China-linked group named Warlock was recently found exploiting Microsoft SharePoint vulnerabilities to deploy ransomware. [3][6]

Share

In short

  • Cyber espionage group TA419 has targeted U.S. AI policy experts with credential phishing campaigns.
  • The attacks impersonated economists, policymakers, and an Anthropic employee in February 2026.
  • The phishing scheme relies on adversary-in-the-middle tactics to steal Microsoft credentials and session cookies.

Sources

Every paragraph above points to the numbered items it rests on. Read the originals here.

  1. [1]China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingThe Hacker News, 15h ago (the report this story comes from)
  2. [2]China-Linked TA419 Hackers Target US AI Policy Experts With Credential Phishing Attacksgbhackers.com, 2d ago

Background

  1. [3]Cyberwarfare and China on Wikipedia
  2. [4]Mohamed Belhocine on Wikipedia
  3. [5]Phishing on Wikipedia
  4. [6]China-linked group Warlock exploits SharePoint flaws to deploy ransomware FTMQ News, 1d ago

Our newsroom writes these reports with the help of software, from the 6 sources listed and nothing else, and checks them against those sources. Facts can still be wrong or move on; the originals are the record. Spotted a mistake? Write to daniel@monsterkong.com.

Earlier reports of ours on the same people and subjects.

More in Cybersecurity

Get the day in one email

Reports like this one, the top news of the last 24 hours, every morning. Free, one email a day; readers can comment under every report.

By signing up you agree to our terms and privacy policy. Unsubscribe any time.

Comments

Loading

Join the conversation

Comments are open to readers of our daily email: the top news of the last 24 hours, every morning, free. Sign up and the comment box opens.

Already on the list? Enter the same address and we will send a sign-in link.

By signing up you agree to our terms and privacy policy. Unsubscribe any time.