P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Fake AI committee, borrowed names: all three sender addresses Proofpoint lists are consumer webmail

Proofpoint says a China-aligned group it tracks as TA419 invited US AI policy experts to a fictitious advisory committee, using borrowed names on consumer webmail. The report gives no victim count and no evidence that AI wrote the lures, so the label names the topic, not the tool.

By Parminder Kumar Sharma · · 20 min read

Editorial illustration for the briefing: Fake AI committee, borrowed names: all three sender addresses Proofpoint lists are consumer webmail

Three sender addresses, and none of them an institution

Proofpoint's indicator list for its July 2026 phishing campaigns names three attacker-controlled sender addresses. All three are on consumer webmail services: two at mail[.]com and one at outlook[.]com. The names in front of them were those of a former Principal Deputy Director of the White House Office of Science and Technology Policy and a prominent economist, and the messages invited readers to join an "AI Policy Advisory Committee" that Proofpoint calls fictitious, or to contribute to a Senate committee report.

That count is ours, taken from the indicator table in Proofpoint's report of 1 October 2026. It counts listed addresses, so it does not show how many messages were sent, how many people were targeted, or whether any account was taken over. It does not show that every message used webmail, only that the three addresses Proofpoint chose to list all do. It does not show who was behind the emails. And it says nothing about artificial intelligence writing them, which is what the headline label "AI phishing" invites a reader to assume.

The Register's story is the pointer to this briefing and Proofpoint's report is the source, read in full with its five figures. Reuters, Nextgov/FCW and CyberScoop are used where they add something the report does not carry, and are marked as secondary each time. Facts are as at the evening of 1 October 2026, British Summer Time.

What Proofpoint reported, and what it left out

Proofpoint, a cybersecurity vendor with an email security business, tracks the group as TA419 and calls it China-aligned and espionage-motivated. It says it has seen the group send targeted credential phishing to people at US and Japan-based think tanks, defence contractors, universities and law firms since at least April 2025, and that the activity had not been reported publicly before, so at least 17 months of observed activity became public on 1 October 2026 (our arithmetic from April 2025). It assesses that the activity likely supports wider Chinese intelligence objectives. As a vendor that sells email security it has a reason to publish on phishing, and a view bounded by what its products and researchers see; the report does not say how it saw these campaigns.

The report has no separate attribution section. It offers the group's long-standing interest in defence, national security, energy, international relations and foreign policy, the fit between that and AI policy amid export controls and distillation accusations, and a description of the group's infrastructure: Cloudflare in front of its domains, registrations typically through NameSilo, and one self-signed TLS certificate, organisation name Castro Inc, found on servers that sent the mail. That infrastructure ties incidents to one cluster; it does not by itself point to a country, which is our reading. Reuters, describing what Proofpoint told it, lists malware, infrastructure and targeting as the basis, while the published report describes a phishing kit and names no malware family. The report states no confidence level, gives no alias or overlap with any other vendor's name for the group, and names no Chinese agency or contractor. CyberScoop reads it the same way: no direct link to the Chinese government. That is a vendor's assessment from a vendor's own telemetry. China-aligned is a weaker phrase than the Register's headline, suspected Chinese spies, and Proofpoint's 2024 report on a different cluster stated its limits outright: it could not attribute that activity to a specific state objective with high confidence.

Table 1. What Proofpoint's report states and does not state. Source: Proofpoint Threat Insight, 1 October 2026, text and Figures 1 to 5; entries marked Reuters are from its account of Proofpoint's comments.

QuestionStated in the reportNot stated
Who and whenProofpoint, 1 October 2026. July campaigns from 8 July 2026. One earlier email in February 2026.How Proofpoint saw the campaigns. How many messages were sent.
Actor and basisTA419, China-aligned and espionage-motivated. Likely supports Chinese intelligence objectives. Active since at least April 2025.A confidence level. Aliases or overlap with other vendors' names. A named agency or contractor.
The lureA fictitious AI Policy Advisory Committee, or a contribution to a Senate Committee on Foreign Relations report on AI export controls and supply chains.How many variants were used beyond two screenshots.
Who was impersonatedLynne Edwards Parker, former Principal Deputy Director of OSTP, and Heidi Crebo-Rediker, economist and foreign policy expert, in July. An unnamed senior Anthropic employee in February.The Anthropic employee's name or role. A Reply-To address. Any statement from the people or the company.
Who was targetedAI policy experts at US think tanks, universities and law firms. For the group overall, US and Japan.Any UK target. A count (Reuters: fewer than 10 individuals, citing Proofpoint).
What was askedA reply. Then a shortened URL to a fake OneDrive page, a relayed Microsoft 365 and Entra ID sign-in, and captured session cookies.Any malware or attachment payload. How many reached the sign-in. Whether any account was taken over.
AIThe lure topic is AI policy. The targets are AI experts. One impersonated person works at an AI company.Any use of a model to write the lures. Which model. Evidence for either.
Indicators19 domains, 3 sender addresses and 1 certificate fingerprint, first seen from December 2025 to July 2026.Last-seen dates. Whether the domains are still live or removed.

Nextgov/FCW and CyberScoop each say the report does not state whether any account was compromised. Reuters reports that Proofpoint put the targeting at fewer than 10 individuals at a handful of organisations, which is a count of people targeted, not of accounts taken. That figure is not in the published post. As at the evening of 1 October, the sources read for this briefing carry no statement from Anthropic or from Ms Crebo-Rediker, and Nextgov/FCW reports that both did not respond to requests for comment. Ms Parker did respond, as the next section shows. Nothing here suggests that any of the three people impersonated did anything wrong.

The recipients who checked

Two accounts of the July campaign come from people who were not fooled. Reuters quotes one recipient as finding the email slightly off, then checking with others in the field and realising it came from an impostor. Nextgov/FCW reports that Ms Parker confirmed by email that two recipients contacted her through separate channels on 9 July to ask whether she had sent the messages. She told them she had not and alerted colleagues. In both accounts the control was the same: someone asked a person who could answer, by a route the message had not supplied.

It is also a biased sample. The recipients the press can reach are the ones who checked and told someone. Neither the report nor the coverage can say how many did not.

A name on an email is not an identity

The friendly-name fallacy is the belief that a label which sounds trustworthy is a control. This chain relies on three labels in sequence, and the diagram sets what the target sees against what is there at each one.

Left to right diagram of four stages of the TA419 phishing chain, each with a blue box for what the target sees and a pink box for what is there. First email: a named official, from a consumer webmail address, no link shown. Reply: a file said to be attached that is link text to a shortened URL. First domain: a fake OneDrive loading screen on a filtering actor domain. Second domain: a drawn Sign in pop-up over a real address bar showing the actor domain. Outcome: session cookies captured.
Drawn from Proofpoint Threat Insight, 1 October 2026: the Infection Chain section and Figures 1 to 3.

Label one is the display name. The two email screenshots in the report show the sender as a person's name over a mail[.]com address. A mail client that shows only the name makes the message look as if that person sent it. Proofpoint calls these addresses attacker-controlled, and uses "spoofing" in the loose sense of impersonating an identity. The screenshots and the indicator list show mailboxes at consumer services carrying a borrowed name. They do not show anyone's domain being forged, which matters because authentication results describe the mailbox, not the person. The quoted copy of the first message in the report's first screenshot also carries a red external-sender tag, which suggests the recipient's mail system flagged it and the recipient replied anyway (our reading; Proofpoint does not comment). A tag says where mail came from, not whether the person is who the name claims. Microsoft's documentation makes the same point for lookalike domains: an impersonating domain can be registered with email authentication records configured and still be intended to deceive.

Label two is the committee. The first message, quoted at the foot of the report's first screenshot, asks for a reply and carries no link or attachment, which is what Proofpoint means by a benign conversation starter. It describes a small committee meeting quarterly by videoconference and says membership is as an independent expert, without institutional obligations. That wording also keeps an employer out of the loop, which is our inference, not Proofpoint's. A committee earns trust because committees exist, being asked to join one is flattering, and nobody asks a convenor for credentials before replying. The follow-up in the same screenshot says the sender will be travelling and slow to respond. Whether or not that was deliberate, a verification step has to survive it. Both screenshots show the file name as underlined link text under a sentence saying a file is attached; Proofpoint says the link was a shortened URL.

Label three is the address bar. At the last step the page draws a pop-up window with its own address bar reading login.microsoft.com over a page whose real address bar shows the actor's second-stage domain (Figure 3 in the report). Proofpoint says the kit is a customised version of the open-source Frameless BitB, a browser-in-the-browser design. An address bar drawn by the page is a picture of an address bar. The fake Claude giveaway briefing covers the same technique and the one test that defeats it.

Beyond the July personas, Proofpoint lists four lookalike sender domains used to impersonate organisations rather than people.

Table 2. Lookalike sender domains in Proofpoint's indicator list. Source: Proofpoint Threat Insight, 1 October 2026, Table 1 and the indicator table.

Impersonated, in Proofpoint's wordingDomainFirst seen
Japan-Taiwan Exchange Associationtw-koryu[.]orgMay 2026
The Heritage Foundationheritiages[.]orgMarch 2026
The Heritage Foundationheritiage[.]orgMarch 2026
Shinjirō Koizumi's official website (current Japanese Minister of Defense)shinjirou[.]infoFebruary 2026

The Heritage Foundation's own site is at heritage.org, checked on 1 October. The domain heritiage[.]org is that name with one letter inserted, and heritiages[.]org is two edits away (our arithmetic). Proofpoint does not say what messages these four domains sent, and says only that the group occasionally registers such domains and uses them for campaigns.

What the AI in AI phishing refers to

The Register's headline calls this AI phishing. Read against the report, the word covers the subject of the lures, which is AI policy, the profession of the targets, who are AI experts, and the employer of one person impersonated in February, an AI company. Proofpoint's key findings, overview and conclusion do not say that a language model wrote the emails, do not name a model, and give no evidence of machine-generated text such as repeated phrasing, metadata or a tool artefact.

The post's title uses the word hallucinating, and nothing in its body explains it. The one phrase that could be read otherwise is "AI-related phishing activity", about a different cluster in an earlier report. Proofpoint's May 2024 report on that cluster describes an AI-themed lure sent from a free email account, so the AI there is also the topic.

So "AI phishing" is accurate as a label for the topic and unsupported as a claim about the tooling. The distinction has a practical edge. If the lures were machine-written, a defender might hope to detect that. The two screenshots show fluent, ordinary English on a subject the recipient cares about, and the NCSC has said that bad spelling and grammar are no longer a reliable sign of a scam. Fluent text is not evidence of a model, and it never was evidence of a human. What the topic does is borrow urgency from the news: Proofpoint places the campaigns amid export controls and accusations of model distillation, and the NCSC lists current events among the signs of a scam. The defence has to rest on provenance, not on how the text reads.

Why the usual controls miss this chain

Each control in the table does a real job. None is aimed at this chain at the point where the chain works.

Table 3. Common controls against the chain Proofpoint describes. Sources: Proofpoint; NCSC guidance and FIDO2 paper; Microsoft Learn.

ControlWhat it does hereWhat it does not do
DMARC enforcement on your own domainStops others forging your domain in a From address (NCSC).Nothing about a name on a consumer webmail address, or a lookalike domain with its own valid records.
Link and attachment scanningChecks what a message carries.The first message, as shown, carries no link or attachment. The shortened URL arrives only after a reply.
MFA by code or push, enforced by Conditional AccessStops a stolen password used alone.Proofpoint says the password, MFA code and conditional access checks all succeed in the relay. The NCSC calls such methods inherently phishable.
Phishing-resistant authentication strengthAllows only FIDO2 keys, Windows Hello for Business or certificate sign-in. The credential is bound to the real domain (NCSC).Covers only the users and apps in the policy. Leaving phishable methods available beside it invites the downgrade attacks the NCSC expects. Needs Entra ID P1.
First contact safety tipWarns when a sender is new or rare to the recipient (Microsoft).Does not block the message, and does not say whether the name is real.
Awareness trainingHelps with some messages.The NCSC says no training can teach people to spot every phishing attempt.

The one control in the table that changes the outcome without relying on a person's judgement is the fourth, and the NCSC's caveat is the part to act on: adding a passkey beside the old methods does not remove the old methods. Proofpoint's own recommendation is phishing-resistant, origin-bound authentication such as passkeys for organisations in scope. One scope note: the NCSC paper compares credentials for personal use and says its findings likely hold for organisations but have not been formally assessed for them. Binding sessions to a device does not fill the gap yet either. As read on 1 October, Microsoft's Token Protection page lists browser-based support as a preview limited to selected web apps that access Azure Resource Manager, and the relay here yields browser session cookies.

Where the coverage and the report differ

Where the news coverage and Proofpoint's page disagree, this briefing follows the page.

  • The Register's headline says an Anthropic exec. Proofpoint says a prominent employee in its key findings and a senior employee in the body, and does not name the person or the role.
  • The Register says the group uses dozens of phishing and spoofed-sender domains and addresses. Proofpoint's list holds 19 domains, 3 addresses and 1 certificate fingerprint, 23 rows in all (our count).
  • CyberScoop lists the World Economic Forum among the organisations whose lookalike domains were registered. Proofpoint's table names the Japan-Taiwan Exchange Association, The Heritage Foundation and a Japanese defence minister's website.
  • Reuters's account of the attribution mentions malware. The published report describes a phishing kit and names no malware family.

What the indicators can and cannot do

Proofpoint publishes 23 indicators: 15 credential-phishing domains (8 first-stage and 7 second-stage), 4 lookalike sender domains, 3 sender addresses and a certificate fingerprint (our count of its table). Fourteen of the 15 phishing domains contain a file-sharing or cloud word such as share, sync, file or cloud (our count of the names), which makes them look like ordinary plumbing in a proxy log. That reading is our inference.

Two derived points matter for a hunt. First, no listed indicator was first seen later than July 2026, so each is at least 62 days old on 1 October. The earliest first-seen month is December 2025: from 1 December to 1 October is 304 days. Microsoft's advanced hunting holds 30 days of raw Defender XDR data unless a Sentinel workspace extends it, so a hunt over the default window sees only recent traffic and misses the months in which these domains were first used. First seen is not last seen, so recent traffic is still possible. Second, the actor rotates: eight first-stage and seven second-stage domains with first-seen months from December 2025 to July 2026. The list records infrastructure already used, not what comes next.

To-scale timeline from April 2025 to October 2026. Bars show the 19 listed domains by first-seen month: 2 in December 2025, 5 in February, 6 in March, 1 in April, 3 in May, 2 in July. July campaigns began 8 July, 85 days before the 1 October report. The July pair was registered about 49 days before that. Every indicator was first seen at least 62 days before the report, and raw hunting data covers 30 days.
Drawn from Proofpoint's indicator table and Figure 4, and Microsoft Learn on advanced hunting. The 20 May position is read off the chart.

The report's Figure 4 plots registration dates. Read off the chart, the July pair was registered on or about 20 May, about 49 days before the 8 July start, on the assumption that its gridlines mark month starts; if they mark mid-month the gap is about 35 days. Twelve of the 19 domains were first seen at least a calendar month after the date plotted for their registration, six in the same month, and one, heritiages[.]org, is listed as first seen in March but plotted in April, so the report's table and chart disagree there. Treat the dates as approximate. The practical point is that a block on domains registered in the last 30 days would not have caught the July pair on 8 July on either reading, while a 60-day window would have. Whether that is worth its false positives is a local decision.

The UK angle, and what is sourced

Proofpoint's report names US and Japanese targets and mentions no UK organisation, so there is no sourced claim that UK organisations were targeted by this campaign. Two things are sourced and two are inference. Sourced: the chain targets Microsoft 365 and Entra ID accounts through a first-party Microsoft application. Sourced: on 30 September, the day before the report, MI5 published an espionage alert saying that more than 100 UK-linked academics had contributed to projects funded via the China General Technology Research Institute, with AI among the topics, and pointing institutions to Trusted Research guidance. That is a different mechanism, funded collaboration rather than phishing, and the alert does not mention TA419. We read the alert line by line in our briefing on it.

Inference: any UK organisation on that platform is within reach of the kit, and UK policy staff, think tanks, universities and law firms working on AI are a population of the same kind as the one Proofpoint describes. The NCSC's phishing guidance already expects targeted, personalised phishing against named staff, built from what an organisation publishes about them. Earlier briefings give context on the method: an invitation lure from a different actor where the first message also carries nothing to scan, and a kit that steals tokens rather than passwords.

What to do, in the order worth doing it

Take this with you

For UK organisations that work on AI policy or research

  • Name the check for committee, advisory board and report invitations. Look up the named person or body through a route you find yourself, not the reply address or any number in the message, and confirm by phone, in person or through an existing contact before replying. Proofpoint advises verifying unexpected subject-matter outreach through another independent medium, and the NCSC advises confirming important email requests by a second channel.
  • Tell the people in scope (policy and research staff, external affairs, senior leaders, anyone on outside panels) that in this chain the reply is the first step of the attack, and that an invitation from a famous name at a consumer webmail address is a reason to check. Make clear that nobody is blamed for asking, or for reporting a mistake.
  • Make the sender visible. Show the full address in the mail client and turn on the first contact safety tip. Where you license Defender for Office 365, add the real addresses of public figures your staff deal with, and of your own leaders, to user impersonation protection so a matching name on a different address is flagged. By default no sender addresses are configured for it.
  • Publish SPF, DKIM and DMARC at enforcement on every domain you own, as the NCSC advises, so your people cannot be impersonated against others. Do not read a pass on incoming mail as proof of identity: it says the mailbox belongs to its domain, not that the person is the one named.
  • Move in-scope accounts to the phishing-resistant authentication strength in Conditional Access (FIDO2 security keys, Windows Hello for Business or certificate-based sign-in) and remove the phishable methods for those users rather than leaving them alongside. This needs Microsoft Entra ID P1.
  • Hunt back through mail, proxy and DNS logs for the 19 domains, the 3 sender addresses and the certificate fingerprint in Proofpoint's list, and the server address 108.61.163[.]187 shown in its Figure 5, for as far back as your retention allows. That is more than 30 days of raw Defender XDR data unless a Sentinel workspace extends it. Treat the list as a floor, because the actor registers new domains.
  • Prepare the response for a user who replied or signed in after such a message. Revoke the user's sessions as well as resetting the password, because the stolen item is the session, then review that user's sign-in logs from the time of the message. Microsoft's emergency steps include blocking new sign-ins and Revoke sessions, and note that applications holding their own session tokens end them only when they expire.
  • Report. Forward the suspicious invitation to the NCSC at report@phishing.gov.uk, tell the real person or body being impersonated through a channel you already use so they can warn their own contacts, and report any loss or compromise to Report Fraud (England, Wales and Northern Ireland) or Police Scotland on 101.
  • If you convene advisory committees yourself, publish how invitations arrive: which role sends them, from which domain, by which channel. A real committee that tells recipients what a genuine invitation looks like gives them something to check against, as the NCSC suggests for outgoing communications generally.

The question that exposes the gap

Proofpoint's recommendations tell individual targets to treat unsolicited subject-matter outreach as a plausible pretext stage. The NCSC advises verifying important email requests through a second channel, and its examples are payments and bank details. An invitation to join a committee looks like neither, which is the gap this lure uses. A fake committee needs no vulnerability and no payload. It needs a recipient who believes that being asked is a credential.

If someone on your team received this invitation tomorrow, from a name they admire and an address they did not read, who would they ask, and how would that person know the answer?

Key facts

Sources

  1. PrimaryPrimary report, Threat Insight post of 1 October 2026 by Mark Kelly and the Proofpoint Threat Research Team. Read in full with its five figures: the TA419 attribution, lure, infection chain, infrastructure, indicator table and recommendations.Proofpointaccessed 2026-10-01
  2. PrimaryProofpoint's 16 May 2024 report on UNK_SweetSpecter, read in full. Used only to establish what the phrase AI-related phishing activity meant in Proofpoint's earlier usage: an AI-themed lure from a free email account.Proofpointaccessed 2026-10-01
  3. PrimaryEspionage Alert of 30 September 2026 on the China General Technology Research Institute. Used only for UK context: more than 100 UK-linked academics, AI among the topics, and the pointer to Trusted Research guidance.MI5 (Security Service)accessed 2026-10-01
  4. PrimaryPhishing attacks: defending your organisation, reviewed 13 February 2024. Used for the layered approach, second-channel verification, DMARC scope, digital footprint of high-profile staff, outgoing communications and reporting culture.UK National Cyber Security Centreaccessed 2026-10-01
  5. PrimaryHow to report a scam email. Used for the reporting address and the Report Fraud and Police Scotland routes.UK National Cyber Security Centreaccessed 2026-10-01
  6. PrimaryHow to spot a scam email, text message or call. Used for the statement that bad spelling is no longer a reliable sign and for current events as a lure signal.UK National Cyber Security Centreaccessed 2026-10-01
  7. PrimaryPaper of 23 April 2026 comparing traditional credentials and FIDO2 credentials for personal use. Used for adversary-in-the-middle phishing, origin binding and downgrade attacks, with its scope caveat.UK National Cyber Security Centreaccessed 2026-10-01
  8. PrimaryEmail security and anti-spoofing guidance for IT managers. Used for what SPF, DKIM and DMARC do on your own domains.UK National Cyber Security Centreaccessed 2026-10-01
  9. PrimaryAnti-phishing policies in Microsoft 365. Used for the first contact safety tip, user and domain impersonation protection, their defaults, and the point that an impersonating domain can have authentication configured.Microsoft Learnaccessed 2026-10-01
  10. PrimaryConditional Access authentication strengths. Used for the built-in phishing-resistant strength and the Entra ID P1 requirement.Microsoft Learnaccessed 2026-10-01
  11. PrimaryRevoke user access in an emergency in Microsoft Entra ID. Used for the Revoke sessions step and the note on application session tokens.Microsoft Learnaccessed 2026-10-01
  12. PrimaryAdvanced hunting overview in Microsoft Defender XDR. Used for the 30 days of raw data and the Sentinel route to longer retention.Microsoft Learnaccessed 2026-10-01
  13. PrimaryToken Protection in Microsoft Entra Conditional Access. Used for the current platform and browser coverage of session-token binding.Microsoft Learnaccessed 2026-10-01
  14. PrimaryThe organisation's own site, used only to confirm its real domain for the lookalike comparison.The Heritage Foundationaccessed 2026-10-01
  15. Reported byNews story of 1 October 2026 that pointed to the Proofpoint report. Used for its headline wording and its description of the indicator list, compared against the primary.The Registeraccessed 2026-10-01
  16. Reported byReuters report of 1 October 2026 on the Proofpoint findings. Used for the fewer than 10 individuals figure attributed to Proofpoint, the account of the attribution basis, and a recipient who checked with colleagues.Reuters (syndicated by CP24)accessed 2026-10-01
  17. Reported byReport of 1 October 2026 by David DiMolfetta. Used for the impersonated former official's account that two recipients contacted her on 9 July, and for the statement that Anthropic and the second impersonated person did not respond to requests for comment.Nextgov/FCWaccessed 2026-10-01
  18. Reported byReport of 1 October 2026. Used for its reading that the report does not directly link the activity to the Chinese government, and for one organisation it lists that the primary does not.CyberScoopaccessed 2026-10-01

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

How often

Every new briefing in one email, at 7am, or at 7am, 12:30pm and 6pm. Nothing is sent when nothing is new. Unsubscribe any time.