A China-aligned group (TA419) impersonated well-known U.S. figures to lure AI policy experts into a fake OneDrive/Microsoft 365 login that could steal session cookies even when MFA is enabled. Separately, two U.S. airmen were sentenced for a multi-year business email compromise scheme where they phished employee credentials and sent spoofed emails to redirect business payments.
How the AI Policy Phishing Attack Worked
TA419, a China-aligned espionage group, built credibility by impersonating a former White House OSTP official and an economist, and in a separate instance posed as an Anthropic employee. The campaign began with benign outreach, often framed as an invitation to discuss AI policy, aimed at researchers, think tank staff, university faculty, and law firm personnel. Once a target replied, they were directed to what appeared to be a shared OneDrive document requiring a Microsoft 365 sign-in.
The critical technical element was the adversary-in-the-middle proxy sitting between the victim and the real Microsoft login page. This allowed the attackers to capture session cookies even when MFA was enabled, effectively neutralizing a control many organizations rely on as a primary defense.
Why the Pretext Succeeded
The attack succeeded because it relied on layered trust rather than a single suspicious email. A credible identity, combined with a non-threatening first message and only later a request to click a link and log in, reduced suspicion at each step. By the time the victim reached the fake OneDrive page, the interaction already felt like a legitimate professional exchange, and the login flow looked authentic even though it was proxied.
The Separate Airmen BEC Scheme
In an unrelated case, two U.S. airmen ran a business email compromise scheme over nearly two years. They phished employee email credentials and used spoofed emails to redirect legitimate business payments, diverting more than $1.68 million from one victim and over $720,000 from another. This case illustrates how credential theft can be monetized directly through payment fraud rather than espionage.
What to Watch For
- Unexpected outreach that leverages a known or high-profile name to build quick credibility
- A request to click a document link and then sign in to Microsoft 365, especially from an unfamiliar message thread
- Login behavior that feels slightly off, even on a page that otherwise looks legitimate
- Any email requesting a change to where a payment should be sent
- Sender context that does not match the history of prior communications
Building Resistance
Organizations handling AI policy research, legal work, or finance operations should train staff to treat document-sharing invitations with the same scrutiny as direct credential requests. Accessing OneDrive or Microsoft 365 directly, rather than through an emailed link, reduces exposure to AitM proxies. For payment-related requests, out-of-band verification through a known phone number or an established approval workflow closes the gap that spoofed emails exploit, regardless of how convincing the message appears.
Key findings
- Proofpoint reported TA419 impersonated prominent individuals to phish AI policy experts across think tanks, universities, and law firms.
- After initial “benign outreach,” victims were directed to a fake OneDrive page using an adversary-in-the-middle (AitM) proxy to capture session cookies, potentially bypassing MFA.
- Two U.S. airmen were sentenced for a BEC operation that stole credentials and used spoofed emails to reroute legitimate business payments, diverting more than $2.4M across two victims.
- Microsoft reported phishing grew as an initial access vector in its incident response cases and “Teams vishing climbed 502%.”
Who’s being targeted
- Commonly targeted roles: Finance / Accounts Payable, Executive assistants, Policy teams / research staff, Legal teams, IT / Identity & Access Management.
- Affected industries: Think tanks / policy organizations, Legal services (law firms), Education (universities), Government.
- Attack channels: email, website.
- Impersonated: Former White House OSTP official (or other credible AI policy figure), A legitimate employee/vendor contact involved in business payments.
Red flags to watch for
- Unexpected outreach leveraging a high-profile identity to create credibility
- Being redirected to a “fake OneDrive page” for Microsoft 365 sign-in
- Login flow behaves unusually (proxy/AitM behavior) even though the page looks legitimate
- Payment destination changes requested over email
- Sender address is spoofed or the email thread context doesn’t match prior interactions
- Pressure to act quickly or treat the request as routine without verification
Frequently asked questions
How did TA419 bypass multi-factor authentication?
Targets who replied to initial benign outreach were sent to a fake OneDrive page that passed the Microsoft 365 sign-in through an adversary-in-the-middle proxy, capturing session cookies even when MFA was used.
Who did TA419 impersonate to gain credibility?
TA419 impersonated a former White House OSTP official, an economist, and also posed as an Anthropic employee to phish AI policy experts at think tanks, universities, and law firms.
How did the airmen BEC scheme cause financial losses?
The airmen phished employee email credentials and used spoofed emails to redirect business payments, diverting more than $1.68 million from an Iowa victim and over $720,000 from an Ohio victim.
What should finance teams do to prevent payment redirection fraud?
Require out-of-band verification, such as a phone call to a known number, for any request to change payment destinations, even if the email appears to come from a known employee.
Read the video transcript
Imagine this: an email from a former White House AI advisor wants your input on an AI policy paper. You reply, they send a OneDrive link. The page looks exactly like Microsoft 365, but it’s an adversary-in-the-middle proxy quietly stealing your session cookies, so they’re in even if you used MFA. Same playbook hits money too: two U.S. airmen stole over $2.4 million by phishing employee credentials, then sending calm, routine emails that quietly changed where business payments should go. Your move: if an impressive name sends a document link or anyone emails to change payment details, don’t click or approve it from the email, open Microsoft 365 or our payment system yourself and check from there.