Between June and July 2026, researchers at multiple cybersecurity firms detected a coordinated phishing campaign targeting AI policy experts across the United States. The attackers did not send generic spam. They researched their targets, impersonated specific people from known organisations, and focused on the institutions that shape US AI regulation.
The targets included researchers at leading universities, staff at think tanks, law firms representing tech companies in regulatory matters, and employees at AI companies including Anthropic. At least one message impersonated a senior Anthropic employee, according to reporting from The Washington Post and Recorded Future.
According to The Hacker News, the campaign was attributed to a suspected Chinese state-sponsored group. The goal was credential theft — stealing email or cloud access to the email systems, file stores and communication channels used by the people who advise Congress and the executive branch on AI policy.
The campaign did not rely on generic attachments or urgent-looking warnings. Instead:
They used real names and roles. Messages impersonated a former White House AI policy official, an AI researcher at a major university, and staff from Anthropic. Not a "Federal Official" — a specific person who existed and whose role the attacker had verified.
They referenced shared context. Messages mentioned specific conferences, policy initiatives or research areas that the target was known to work on. A legal expert received a message about a specific upcoming regulatory hearing. A researcher got a note about a paper they had recently published.
The payload was a cloud account login. Rather than a .exe or macro, the link led to a convincing fake login page — usually for Google Workspace or Microsoft 365. Targets who entered credentials gave the attacker access to their email, OneDrive, and any shared files.
They went after institutional mailboxes, not personal ones. Because policy work lives in shared team email and drives, compromise of one person's credentials meant access to the strategy documents, meeting notes and correspondence of an entire team.
Once inside, they had access to:
None of this was classified, but all of it was sensitive because it was not yet public. The advantage to a foreign government is in timing — knowing the direction of US AI policy before it is announced, and potentially before final decisions are made.
The campaign was detected when several targets reported unusual login activity and suspicious forwarding rules on their inboxes — a common attacker tactic to exfiltrate mail while the original owner stays unaware. Email security vendors and threat intelligence firms correlated the phishing emails, examined the infrastructure, and attributed the campaign to a known Chinese-nexus group.
According to reporting from CrowdStrike and Mandiant:
The campaign has since been disrupted through abuse reports and domain takedowns, but researchers note that the tactic — impersonation of trusted figures to target policy-making institutions — is likely to resurface with different identities and targets.
Policy institutions are an unusual target for cyberspying because their value is not in a single database or product — it is in influence. When attackers compromise the email of a White House official, a Congressional staffer, or a researcher who advises both, they gain visibility into the decision-making process itself. That is hard to detect with network monitoring alone, because the attacker is not stealing a database. They are reading correspondence.
The same pattern applies inside any organisation where strategy decisions, customer conversations, or product roadmap discussions live in shared email and documents. If an attacker gains access to a handful of team inboxes, they can watch the organisation think.
Obichat is a workspace for teams to collaborate on multi-model conversations. It separates team discussions from the broader internet and your consumer email provider, keeping sensitive conversations — strategy, customer updates, product decisions — in a controlled space with clear audit trails.
Two aspects matter directly for this incident:
No forwarding to external accounts. Obichat conversations cannot be forwarded to a Gmail or Outlook mailbox that an attacker could compromise. If a team member's email is stolen, the attacker sees the messages their email client synced — not the full history of everything the team discussed.
Access logs tied to identity. Every Obichat message is logged with the user, timestamp, and any device information your org has registered. If a team member's password is compromised and someone else logs in, the activity shows up in Audit Logs with a different IP address and device profile. A SOC team or security operations centre can set up alerts for impossible travel (login from Asia, then login from the US five minutes later) or access from unknown devices.
Invite control. Workspace members and guests are managed explicitly, not through ambient email access. A compromised email account cannot auto-add itself to Obichat channels — that requires an invite or an org admin action.
This does not prevent someone from emailing you a fake login page. That belongs to your phishing training and email security. What it does is reduce the value of a stolen email password for an attacker who was hoping to read your strategy, customer and team conversations.
The attackers in this campaign did not find a zero-day or a leaked password. They researched their targets, built a convincing story and sent an email. That works on email because email is how teams talk, and email is also where any attacker with a password can read everything.
So the question is not is our email provider secure? It is: if someone steals the password to your team's shared mailbox, what conversations would they find, and where else should those conversations be happening?
Explore Obichat or talk to us about moving strategy, customer and team conversations to a workspace that is separate from your email, with full audit trails and no forwarding to external accounts.
Obiguard sits in front of every AI request your organization makes — screening prompts and outputs against the guardrails, compliance frameworks, and audit trails that stories like this one make necessary.
See how it works →