Chinese Spy Phish + Airmen BEC Sentenced

Security Week Feed · High sophistication
Last updated October 5, 2026

A China-aligned group (TA419) impersonated well-known U.S. figures to lure AI policy experts into a fake OneDrive/Microsoft 365 login that could steal session cookies even when MFA is enabled. Separately, two U.S. airmen were sentenced for a multi-year business email compromise scheme where they phished employee credentials and sent spoofed emails to redirect business payments.

How the AI Policy Phishing Attack Worked

TA419, a China-aligned espionage group, built credibility by impersonating a former White House OSTP official and an economist, and in a separate instance posed as an Anthropic employee. The campaign began with benign outreach, often framed as an invitation to discuss AI policy, aimed at researchers, think tank staff, university faculty, and law firm personnel. Once a target replied, they were directed to what appeared to be a shared OneDrive document requiring a Microsoft 365 sign-in.

The critical technical element was the adversary-in-the-middle proxy sitting between the victim and the real Microsoft login page. This allowed the attackers to capture session cookies even when MFA was enabled, effectively neutralizing a control many organizations rely on as a primary defense.

Why the Pretext Succeeded

The attack succeeded because it relied on layered trust rather than a single suspicious email. A credible identity, combined with a non-threatening first message and only later a request to click a link and log in, reduced suspicion at each step. By the time the victim reached the fake OneDrive page, the interaction already felt like a legitimate professional exchange, and the login flow looked authentic even though it was proxied.

The Separate Airmen BEC Scheme

In an unrelated case, two U.S. airmen ran a business email compromise scheme over nearly two years. They phished employee email credentials and used spoofed emails to redirect legitimate business payments, diverting more than $1.68 million from one victim and over $720,000 from another. This case illustrates how credential theft can be monetized directly through payment fraud rather than espionage.

What to Watch For

  • Unexpected outreach that leverages a known or high-profile name to build quick credibility
  • A request to click a document link and then sign in to Microsoft 365, especially from an unfamiliar message thread
  • Login behavior that feels slightly off, even on a page that otherwise looks legitimate
  • Any email requesting a change to where a payment should be sent
  • Sender context that does not match the history of prior communications

Building Resistance

Organizations handling AI policy research, legal work, or finance operations should train staff to treat document-sharing invitations with the same scrutiny as direct credential requests. Accessing OneDrive or Microsoft 365 directly, rather than through an emailed link, reduces exposure to AitM proxies. For payment-related requests, out-of-band verification through a known phone number or an established approval workflow closes the gap that spoofed emails exploit, regardless of how convincing the message appears.

Key findings

  • Proofpoint reported TA419 impersonated prominent individuals to phish AI policy experts across think tanks, universities, and law firms.
  • After initial “benign outreach,” victims were directed to a fake OneDrive page using an adversary-in-the-middle (AitM) proxy to capture session cookies, potentially bypassing MFA.
  • Two U.S. airmen were sentenced for a BEC operation that stole credentials and used spoofed emails to reroute legitimate business payments, diverting more than $2.4M across two victims.
  • Microsoft reported phishing grew as an initial access vector in its incident response cases and “Teams vishing climbed 502%.”

Who’s being targeted

  • Commonly targeted roles: Finance / Accounts Payable, Executive assistants, Policy teams / research staff, Legal teams, IT / Identity & Access Management.
  • Affected industries: Think tanks / policy organizations, Legal services (law firms), Education (universities), Government.
  • Attack channels: email, website.
  • Impersonated: Former White House OSTP official (or other credible AI policy figure), A legitimate employee/vendor contact involved in business payments.

Red flags to watch for

  • Unexpected outreach leveraging a high-profile identity to create credibility
  • Being redirected to a “fake OneDrive page” for Microsoft 365 sign-in
  • Login flow behaves unusually (proxy/AitM behavior) even though the page looks legitimate
  • Payment destination changes requested over email
  • Sender address is spoofed or the email thread context doesn’t match prior interactions
  • Pressure to act quickly or treat the request as routine without verification
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did TA419 bypass multi-factor authentication?

Targets who replied to initial benign outreach were sent to a fake OneDrive page that passed the Microsoft 365 sign-in through an adversary-in-the-middle proxy, capturing session cookies even when MFA was used.

Who did TA419 impersonate to gain credibility?

TA419 impersonated a former White House OSTP official, an economist, and also posed as an Anthropic employee to phish AI policy experts at think tanks, universities, and law firms.

How did the airmen BEC scheme cause financial losses?

The airmen phished employee email credentials and used spoofed emails to redirect business payments, diverting more than $1.68 million from an Iowa victim and over $720,000 from an Ohio victim.

What should finance teams do to prevent payment redirection fraud?

Require out-of-band verification, such as a phone call to a known number, for any request to change payment destinations, even if the email appears to come from a known employee.

Read the video transcript

Imagine this: an email from a former White House AI advisor wants your input on an AI policy paper. You reply, they send a OneDrive link. The page looks exactly like Microsoft 365, but it’s an adversary-in-the-middle proxy quietly stealing your session cookies, so they’re in even if you used MFA. Same playbook hits money too: two U.S. airmen stole over $2.4 million by phishing employee credentials, then sending calm, routine emails that quietly changed where business payments should go. Your move: if an impressive name sends a document link or anyone emails to change payment details, don’t click or approve it from the email, open Microsoft 365 or our payment system yourself and check from there.

Similar attacks

TA419 Phishes AI Policy Experts With Microsoft AitM

TA419 Phishes AI Policy Experts With Microsoft AitM

China-aligned threat actor TA419 ran real credential-phishing campaigns targeting U.S. AI policy experts at think tanks, universities, and law firms. The operation used trust-building outreach followed by a shortened link that redirected victims through checks to a fake Microsoft/OneDrive sign-in…

October 4, 2026
Fake AI Experts Lure Think Tanks Into M365 Phish

Fake AI Experts Lure Think Tanks Into M365 Phish

A China-aligned group (TA419) targeted US AI policy experts by impersonating well-known AI and policy figures and sending friendly “collaboration” emails. If the target engaged, the attackers redirected them through multiple URLs to a fake Microsoft login pop-up designed to steal Microsoft 365…

October 2, 2026
TA419 Poses as White House to Steal Cloud Logins

TA419 Poses as White House to Steal Cloud Logins

A China-aligned espionage group (TA419) targeted U.S. AI policy experts by impersonating well-known public figures and sending credible policy-related invitations. After victims replied, the attackers sent shortened links that led to a fake OneDrive login designed to capture passwords, MFA codes,…

October 2, 2026
Phish Adds Passkey That Survives Reset

Phish Adds Passkey That Survives Reset

Researchers described iAuthFlow v2, a phishing toolkit that steals a live Google login session and then uses that access to enroll an attacker-controlled passkey. Because passkeys are separate login methods, the attacker can often get back into the account even after the victim changes their…

August 24, 2026
Fake AI Advisory Invites Steal M365 Logins

Fake AI Advisory Invites Steal M365 Logins

Researchers say a China-aligned group (TA419) impersonated well-known AI policy figures and an Anthropic executive to lure US AI policy experts into replying to emails about a fake advisory committee or Senate report. Once a target engaged, the attackers sent shortened links that led through a fake…

October 1, 2026
Fake Claude Max Promo Steals Google Logins

Fake Claude Max Promo Steals Google Logins

Researchers found a phishing campaign offering a “free” upgrade to Claude Max to trick people into signing in with Google. The page uses a convincing fake, draggable Google login window (“browser-in-the-browser”) to capture credentials, potentially giving criminals access to email, documents, and…

September 23, 2026