Proofpoint says a group it tracks as TA419 used the identities of prominent U.S. AI and policy figures to make phishing emails look like plausible invitations to collaborate. In July 2026, the lures directed a small number of AI policy specialists toward websites designed to steal login credentials. Proofpoint assessed the activity as China-aligned and potentially aimed at understanding U.S. AI policy; the available reporting does not establish that any account was compromised.
2
4
18
How the phishing campaign worked
The emails proposed AI-related collaborations or initiatives, borrowing the identities of people recipients might recognize. Reported personas included former White House official Lynne Parker, a former State Department economist and a senior Anthropic employee. The messages then steered recipients to credential-phishing websites.
2
4
16
That combination—familiar names and a work-related invitation—was intended to make a request to sign in appear credible. The immediate objective described in the reporting was to capture account credentials, potentially opening access to cloud accounts or email.
4
5
Who was targeted—and what is known about Alex Engler
Proofpoint identified AI specialists at U.S. think tanks, universities and legal-sector organizations as targets. The reported July campaign reached fewer than 10 people, according to coverage of the findings.
2
4
9
The available source material does not provide a verified list of recipients or substantiate Alex Engler as a target. His inclusion should therefore be treated as unconfirmed based on the reporting available here.
10
What supports the China attribution?
Proofpoint tracks the activity as TA419 and describes the group as China-aligned. Reporting says the attribution draws on technical indicators, including malware and infrastructure, as well as the targets selected.
1
2
13
That is Proofpoint’s assessment, not independently conclusive proof in the material available here that the Chinese government directed this specific campaign. The source excerpts do not lay out the underlying technical evidence in enough detail to evaluate it fully.
1
2
What the small target list may suggest
A campaign aimed at fewer than 10 specialists is consistent with a focused attempt to reach people involved in AI policymaking rather than a broad, indiscriminate phishing effort. Proofpoint said the activity may support intelligence-gathering about U.S. AI policy and regulation; other reporting describes the relevant policy areas as AI regulation, export controls and national strategy.
2
3
9
That is a proposed motive, not a confirmed result. The reporting establishes an attempt to steal credentials, but the available sources do not say that the attackers successfully accessed accounts or obtained policy information.
18