US policy experts AI media incident — Oct 2026
The hacking group TA419 impersonated AI experts and government officials to target US policy minds at think tanks and defense contractors via deceptive emails
- Reported date
- Oct 1, 2026
- Target
- US policy experts
The exact incident date was not established. This entry is dated by its source report.
The China-aligned hacking group TA419 has been targeting US policy experts by impersonating prominent figures in the artificial intelligence sector and government. These sophisticated social engineering campaigns have focused on individuals at think tanks, defense contractors, universities, and law firms across the United States and Japan.
What happened
Operating since April 2025, TA419 employs a multi-stage deception strategy to harvest credentials. The process typically begins with seemingly benign emails, such as invitations to join an “AI Policy Advisory Committee,” designed to establish rapport with the target. Once a victim engages, they are directed to a fraudulent login page. To increase the success rate of these credential-harvesting attempts, the attackers utilize a technique that generates a fake browser pop-up window within a legitimate-looking webpage, mimicking an authentic sign-in prompt.
In July 2026, the group impersonated high-profile figures, including Lynne Edwards Parker, the former principal deputy director of the White House Office of Science and Technology Policy. Another target, Alex Engler, a former White House official currently leading the Penn Center on Media, Technology, and Democracy, confirmed receiving such an email but successfully identified the impersonation after consulting with colleagues. This activity follows a similar campaign from February 2026, where the group impersonated a prominent Anthropic employee to target AI policy experts. Cybersecurity researchers expect these impersonation tactics to persist as the group continues to leverage the identities of real-world experts to compromise policy-focused organizations.