Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →TA419 used tailored, professional-sounding outreach about artificial intelligence policy to draw U.S. experts into credential-phishing attempts, according to Proofpoint’s October 1, 2026 report. The July 2026 campaigns impersonated two policy figures; a separate February campaign posed as a senior Anthropic employee. The reported phishing flow was designed to steal Microsoft sign-in credentials and session material, but public reporting does not confirm that any account was compromised.
How TA419 approached AI policy experts
Proofpoint says the activity began on July 8, 2026, with messages aimed at AI policy experts at U.S. think tanks, universities, and law firms. Rather than opening with an obvious login request, the emails used plausible professional invitations and requests for input to encourage recipients to reply.
The July messages impersonated Lynne Edwards Parker, a former principal deputy director of the White House Office of Science and Technology Policy, and economist and foreign-policy expert Heidi Crebo-Rediker. The pretexts included an invitation to join a fictitious “AI Policy Advisory Committee” and a request to contribute to a supposed Senate Committee on Foreign Relations report about AI export controls and supply chains.
After a recipient replied, the actor sent a shortened link said to provide more information. That sequence matters: the first email was a credibility-building approach, while the link arrived later, within an exchange that could feel expected.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware match#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How the campaigns differed
| Timing | Impersonation and pretext | Reported target and next step |
|---|---|---|
| February 2026 | A senior Anthropic employee; the subject line was “Request for Feedback on Military Integration of Claude.” | An AI policy analyst at a U.S. think tank was asked for feedback on the debate over U.S. military use of Claude. The message led to a similar adversary-in-the-middle credential-phishing flow. |
| Beginning July 8, 2026 | Lynne Edwards Parker and Heidi Crebo-Rediker; invitations and requests tied to AI policy, export controls, and supply chains. | AI policy experts at U.S. think tanks, universities, and law firms were approached. After a reply, they received a shortened link leading through redirects to a fake OneDrive-themed page and sign-in flow. |
Proofpoint describes the February activity as a separate campaign from the July outreach. It places both within TA419’s wider pattern of credential-phishing aimed at people in policy and national-security circles.
What the phishing page was designed to do
The July link passed through multiple stages. Proofpoint says the first-stage site displayed a fake OneDrive loading screen and a Cloudflare Turnstile check before redirecting the target to a second-stage sign-in page. The campaigns shared the reported first-stage domain driftshare[.]co and second-stage domain globalfileshareplatform[.]com. These are indicators for defenders, not sites to visit.
Rank #2
- FIDO2 + FIDO U2F certified and supported USB security key
- Secured by NXP semiconductors
- Works in every browser and application without installing any drivers
- Supports desktops, laptops, tablets via USB-A and/or NFC, and supports iOS/Android Phones via NFC
- Helps protect your accounts from phishing and other cyber-attacks. Prevents your devices from unauthorized use.
The final page used an adversary-in-the-middle (AitM) technique: instead of simply showing a fake sign-in form, the phishing service sat between the user and the legitimate sign-in service, relaying the authentication activity while presenting a deceptive browser and sign-in experience. Proofpoint says the flow targeted Microsoft 365 and Entra ID through the first-party OfficeHome application and used a customized version of the open-source Browser-in-the-Browser tool Frameless BitB.
This design can capture both credentials and the session cookies issued after sign-in. As a result, completing a conventional multifactor authentication (MFA) prompt does not necessarily stop this kind of attack: a successful sign-in can produce session material that the intermediary may capture. That describes the method’s capability, not proof that a particular person’s credentials or session were stolen in these campaigns.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
- FIDO2 + FIDO U2F certified and supported USB security key
- Supports Computers, Laptops, Tablets, and Mobile Devices with a USB-C port and/or NFC
- Works without downloading any drivers. Supported OS: Android, Chrome OS, Windows, MacOS, Linux
- Durable design made to last for a long time with everyday use. Water-resistant (IP67)
- Helps protect your accounts from phishing and other cyber-attacks. Prevents your devices from unauthorized use.
What is known about victims and compromise
The public accounts reviewed do not name victims, give a victim or compromise count, or report a success rate. CyberScoop says the report did not identify victims or state whether accounts were compromised. The campaigns establish that targets were approached with a credential- and session-theft design; they do not establish that anyone successfully lost account access.
There is likewise no published population-level statistic that would show how widespread the operation was. The February and July dates identify reported campaign timing, not the number of people contacted or affected.
Rank #4
- FIDO2 SECURITY KEY: A versatile, tamper-evident USB-C authentication device with sensitive presence detection for online security. FIDO 2.0 level 1 and U2F certified
- PASSWORDLESS CONVENIENCE: Replace frustrating passwords with a simple 4-digit PIN for accessing apps and sites. Seamlessly login to web apps and Windows sessions
- BROAD COMPATIBILITY: Works with Windows, Mac, Linux, Apple, iOS, iPhone, Android and USB-C devices. Seamlessly integrates with Identity Providers or Credential Management Systems supporting FIDO2, including Thales, Microsoft, AWS, and Google
- ENHANCED USER ADOPTION: Features a sensitive presence detector on the USB key, providing ease of use and superior security. Certified for U2F and FIDO2, ideal for individuals who want to secure access to their personal online accounts - Microsoft, Google, Twitter, Facebook, GitHub
- THALES: We offer a wide range of FIDO authenticators, providing robust, phishing-resistant MFA that comply with stringent regulations. With almost three decades of experience, Thales is a pioneer in passwordless authentication devices, supported globally by the FIDO Alliance and industry analysts
What the China-linked attribution does—and does not—establish
Proofpoint characterizes TA419 as China-aligned and espionage-motivated, and assesses that the activity likely supports wider Chinese intelligence objectives, including understanding U.S. AI policy and regulation. This is the security firm’s attribution and assessment. CyberScoop notes that the report did not directly link the activity to the Chinese government, so government direction or tasking should not be treated as established fact.
Proofpoint says TA419 has run regular targeted credential-phishing campaigns against people at U.S.- and Japan-based think tanks, defense contractors, universities, and law firms since at least April 2025. It describes the AI-policy focus as an extension of the group’s existing interest in defense, national security, energy, international relations, and foreign policy.
Best Value
- SECURITY KEY FOR ENTERPRISE ACCESS: Supports FIDO2 passkeys and U2F for secure authentication across enterprise IT systems.
- PHISHING-RESISTANT AUTHENTICATION: Enables passwordless login with secure on-device credential storage and PIN-based user verification.
- COMPATIBLE WITH ENTERPRISE SYSTEMS: Works with FIDO2, WebAuthn, and U2F across enterprise, cloud, and modern IT environments.
- DRIVERLESS FIDO2 AUTHENTICATION: FIDO2 works natively with modern browsers and platforms. No drivers required.
- USB AND NFC CONNECTIVITY: Supports authentication via USB-C and NFC. No batteries required.
How policy professionals and organizations can reduce risk
Verify the conversation, not just the sender
Treat unexpected invitations, research requests, and requests for expert feedback as possible pretexts even when they sound relevant to your work. Before opening a link or signing in, confirm the request through a separate, independently obtained channel—for example, a known institutional address or phone number, rather than contact details supplied in the message.
Use phishing-resistant sign-in where available
Proofpoint recommends phishing-resistant, origin-bound authentication such as passkeys for organizations in the scope of this activity. These methods bind authentication to the legitimate site or service, making them more resistant to credential-relay phishing than a password paired with a conventional MFA prompt. Organizations should confirm that their chosen authentication method works with their accounts and required workflows; no single control should be treated as a complete defense.
If you entered credentials after following an unexpected link
Contact your organization’s IT or security team promptly and explain what you entered and whether you completed an MFA prompt. Because an AitM flow may capture session material as well as a password, the team can assess the account and determine the appropriate response rather than assuming a password change alone addresses the exposure.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

