In July 2026, a China-aligned threat actor, TA419, ran credential-phishing campaigns impersonating prominent economists and AI policymakers, including a former White House Office of Science and Technology Policy leader. TA419 targeted AI experts at US think tanks, universities, and legal sector organizations and likely supported Chinese intelligence-gathering objectives. This is the first report ever published on TA419, a group that Proofpoint has tracked since at least April 2025. https://brnw.ch/21x66c4 Our researchers recommend that organizations in the defense, national security, energy, international relations, and foreign policy sectors take note of TA419’s activities. The group will likely continue targeting these industries and spoof the identities of real subject-matter experts. See our blog for a campaign overview, infection chain and infrastructure analysis, and IOCs.
About us
Intent-based protection for every human and every AI agent, across all data.
- Website
-
https://www.proofpoint.com
External link for Proofpoint
- Industry
- Computer and Network Security
- Company size
- 1,001-5,000 employees
- Headquarters
- Sunnyvale, California
- Type
- Privately Held
- Specialties
- Email Security, Collaboration Protection, Data Security & Governance, and AI Security
Employees at Proofpoint
Locations
Updates
-
To close out National Insider Threat Awareness Month, we’re sharing the top quotes from our Proofpoint Power Series event. Thousands of attendees tuned in to discuss insider risk in the AI era. Missed the session? Listen to the recording on demand here: https://lnkd.in/enYATcnP #NITAM
-
Success is never achieved alone. Trust, communication, and support help teams perform under pressure. The same is true for organizations. Protecting people, data, and AI creates the foundation for innovation and growth. Learn more: https://lnkd.in/ea9vJEZs --- Proofpoint is a proud sponsor of Delfi Brea, the world's top-ranked padel player.
-
-
Another step in our commitment to the U.S. Public Sector. Proofpoint is pursuing FedRAMP High (Class D) authorization for our Data Security and Insider Threat Management solutions, building on the Agentic Data and AI Security System we introduced last week. Federal agencies should not have to choose between accelerating AI adoption and maintaining control of their most sensitive information. Our goal is to help them protect that information, understand and reduce the insider risk surrounding it — including the risk introduced by AI itself — and securely embrace the technologies changing how government works. Find out more on our blog: https://lnkd.in/eE3M5sku
-
Join our product experts Pablo Passera and Gary Poduska for a webinar that will explore how Proofpoint OEM can accelerate security product innovation, reduce time-to-market, and enhance detection capabilities without added complexity. Agenda Topics: 🎯 The Market Demand for Detection Intelligence 🎯 The Build-vs-Buy Reality 🎯 Where Proofpoint Emerging Threat Intelligence Fits 🎯 Accelerating Product Innovation 🎯 Strategic Business Value Register now! https://lnkd.in/ePyutV7b
-
-
We're proud to support Claude for Business' Compliance API through integrations that extend data security, DLP, insider risk detection, AI runtime security, and Digital Communications Governance into Claude. Through these integrations, organizations can gain visibility into supported Claude activity, apply existing policies to AI workflows, and flag policy-defined sensitive prompts for review based on activity logs. For customers, the outcome is simple: a more consistent way to monitor people, data, and AI activity through the tools they already use. Learn more about Proofpoint's integrations with Claude: https://lnkd.in/eRhZkKUB https://lnkd.in/dDyYKCjz
The Claude Compliance API now connects to more than 100 security and compliance products, including DLP, SIEM, identity, eDiscovery, and AI security platforms. Security teams can review Claude activity in the tools they already use to monitor the rest of the company. Depending on the integration, those tools can pull in conversations, files, and projects from Claude Enterprise, along with admin activity from Claude Enterprise and the Claude Platform. Claude Enterprise and Claude Platform customers can connect a supported security platform today. Security and compliance companies can apply to build an integration. Learn more: https://lnkd.in/eJEeMATi Current integrations: Above Security, Air, Airia, aizome, Akeyless Security, Akto, Alignmt AI, Apiiro, Artemis Security, Axonius, Bay, Beacon Security, BigID, Bloom Security, Bluebear Security, Bold Security, Brava Security, C1.ai, Capsule Security, Cato Networks, Check Point, CloudEagle.ai, Cloudflare, Clover Security, Concentric AI, Cribl, CrowdStrike, Cyberhaven, Cyera, Dash Security, Datadog, Daylight, Elastic, Eon, eSentire, Evoke Security, Exaforce, ForceAI Security, Forcepoint, Fortinet, Geordie AI, Glow, Grip Security, Hadrius, Harmonic Security, IBM Guardium, Island, KnowBe4, Lasso Security, Linx Security, Microsoft Purview, Mimecast, Mind Security, Mint Security, Netskope, Nightfall AI, Noma Security, Obsidian Security, Okta, Onyx Security, Opal Security, Opsin, Orca Security, Origin, Palo Alto Networks, Pi Security, Pluto Security, Proofpoint, Reco, RelativityOne, ReliaQuest, Reva.ai, Rubrik, Safeguard, SailPoint, Salt Security, Saviynt, SentinelOne, Sentra, Shield, Silverfort, Smarsh, Snyk, Sola Security, Splunk, Strac, Straiker, Sumo Logic, Surf AI, Sysdig, Tenable, Theta Lake, Token Security, Torch Security, Trellix, TrendAI, Twine Security, Valence Security, Vanta, Varonis, Vega, Vero Security, Willow, WithWings, Wiz, Zenity, Zscaler.
-
-
Threat actors are stealing U.S. university .edu credentials and using them to run job scams, fake scholarships, and other advance-fee fraud scams. Our researchers engaged with the fraudsters to learn how they operate. Our new blog explains the team’s findings and shares examples of scams we have observed. https://lnkd.in/eX4VDxKH ⚠️ Organizations in higher education should understand the attack chain to better educate their users, improve detection, and disrupt ongoing activity.
-
When a global manufacturer experienced a #ransomware incident, a fundamental security problem was exposed: lack of visibility into where its data resided. The solve: Expand on its existing Proofpoint email security deployment with Proofpoint unified data security. Now the security team has greater visibility into data at rest and in motion, and the company can adopt AI safely and confidently. Read the full customer story: https://lnkd.in/ecybx5Sj #datasecurity #DSPM #DLP #AIsecurity #datagovernance #dataprivacy
-
-
That's a wrap on #Protect26 in San Diego. Thank you to the CISOs and security practitioners, partners, and community members who joined us to explore AI intent, integration, and innovation. Three days of insights, conversations, and shared perspectives on securing people and data in an AI-driven world. Next up: Our Protect experience hits the road! Stay tuned for events coming to cities near you.
-
Proofpoint’s 2026 Voice of the CISO shows that security programs are making progress against familiar threats while AI, human behavior, identity, and workplace technology reshape the attack surface. See what's rewriting the #CISO agenda, as reported by 1,600 CISOs across 16 markets 👉 https://lnkd.in/e3JDzjks
-