China-Linked Phish Targets AI Policy Experts

CyberScoop · High sophistication
Last updated October 1, 2026

Proofpoint reports a China-aligned espionage group (TA419) targeted U.S. AI policy experts at think tanks, universities, and law firms using phishing emails that impersonated well-known officials and AI industry figures. The attackers tried to start a conversation first, then sent a shortened link that ultimately led to a fake Microsoft OneDrive login page designed to steal cloud credentials and active sessions.

Key findings

  • TA419 impersonated “prominent officials, economists and an employee of AI company Anthropic” to target AI policy experts.
  • The operation focused on “access to cloud accounts held by people at think tanks, universities and law firms.”
  • The attackers used a trust-building workflow: “The initial messages did not immediately request passwords… After a target replied, the group sent a shortened link…”
  • Victims were redirected to “a false Microsoft OneDrive sign-in page” intended to capture “account credentials and active browser sessions.”
  • Proofpoint described it as “an adversary-in-the-middle phishing attack,” where victims may complete MFA while attackers capture session data.
  • Proofpoint says the group used a modified open-source tool: “Frameless BitB.”

Who’s being targeted

  • Commonly targeted roles: Think tank staff, AI policy analysts, University researchers and faculty, Legal (attorneys and paralegals), Executives in policy/research organizations.
  • Affected industries: Think tanks / policy research, Higher education (universities), Legal services (law firms), Defense contractors.
  • Attack channels: email, website.
  • Impersonated: Former White House OSTP official / well-known economist & foreign policy expert, Senior Anthropic employee.

Awareness takeaways

  • Treat “friendly” outreach emails as suspicious when they try to move you into a link-based workflow after you reply.
  • Be cautious with shortened links and multi-redirect chains, these are common ways to hide the true destination.
  • Train users that MFA alone doesn’t prevent all phishing, some attacks can steal an active session even after MFA approval.
  • When an email claims to be from a prominent official or major company, verify the request through a trusted channel before clicking anything.

Red flags to watch for

  • Conversation-first approach designed to build trust before sending a link
  • Shortened link that redirects through multiple websites
  • Unexpected OneDrive/Microsoft login prompt for a policy collaboration invite
  • Highly sensitive/controversial topic used to prompt urgent engagement
  • Impersonation of a recognizable AI company employee
  • Login request that appears during a feedback request
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email: "Invitation to join an AI policy advisory committee" from a former White House OSTP official. Sounds flattering, right? This China-linked group, TA419, doesn’t ask for passwords right away. They chat first, then send a shortened link to "more info" that lands on a fake Microsoft OneDrive login using a Frameless BitB, an adversary-in-the-middle trick that can even capture MFA sessions. Here’s the aha: the OneDrive page looks perfect, but it’s actually a browser-in-the-browser, or BitB, window floating inside the site. It even shows "microsoftonline.com" in a fake address bar while quietly stealing your cloud credentials and active session. If a "prominent official" or Anthropic contact moves you from friendly chat into a shortened link and surprise Microsoft sign-in, stop. Don’t log in there, forward it to security and go to your cloud account from your normal bookmark instead.

Similar attacks

TA419 Phishes AI Policy Experts With Microsoft AitM

TA419 Phishes AI Policy Experts With Microsoft AitM

China-aligned threat actor TA419 ran real credential-phishing campaigns targeting U.S. AI policy experts at think tanks, universities, and law firms. The operation used trust-building outreach followed by a shortened link that redirected victims through checks to a fake Microsoft/OneDrive sign-in…

October 4, 2026
China-Linked TA419 Phishes US AI Policy Experts

China-Linked TA419 Phishes US AI Policy Experts

Proofpoint linked China-nexus actor TA419 to credential-phishing campaigns aimed at U.S. AI policy experts, including people at think tanks. The attacker impersonated well-known AI policymakers and an Anthropic executive, using believable “advisory committee” and “research questions” emails to draw…

October 2, 2026
Chinese Spy Phish + Airmen BEC Sentenced

Chinese Spy Phish + Airmen BEC Sentenced

A China-aligned group (TA419) impersonated well-known U.S. figures to lure AI policy experts into a fake OneDrive/Microsoft 365 login that could steal session cookies even when MFA is enabled. Separately, two U.S. airmen were sentenced for a multi-year business email compromise scheme where they…

October 2, 2026
Fake AI Experts Lure Think Tanks Into M365 Phish

Fake AI Experts Lure Think Tanks Into M365 Phish

A China-aligned group (TA419) targeted US AI policy experts by impersonating well-known AI and policy figures and sending friendly “collaboration” emails. If the target engaged, the attackers redirected them through multiple URLs to a fake Microsoft login pop-up designed to steal Microsoft 365…

October 2, 2026
TA419 Poses as White House to Steal Cloud Logins

TA419 Poses as White House to Steal Cloud Logins

A China-aligned espionage group (TA419) targeted U.S. AI policy experts by impersonating well-known public figures and sending credible policy-related invitations. After victims replied, the attackers sent shortened links that led to a fake OneDrive login designed to capture passwords, MFA codes,…

October 2, 2026
Fake AI Advisory Invites Lure US Policy Targets

Fake AI Advisory Invites Lure US Policy Targets

A China-aligned group (tracked as TA419) impersonated real AI policy figures and sent benign-sounding outreach to people working on AI policy at US and Japanese organizations. Once targets replied, the attackers sent a shortened link that ultimately led to a fake OneDrive/Microsoft 365 login page…

October 1, 2026