Fake AI Advisory Invites Steal M365 Logins

The Register Security · High sophistication
Last updated October 1, 2026

Researchers say a China-aligned group (TA419) impersonated well-known AI policy figures and an Anthropic executive to lure US AI policy experts into replying to emails about a fake advisory committee or Senate report. Once a target engaged, the attackers sent shortened links that led through a fake OneDrive/Cloudflare check to a credential-phishing page designed to steal Microsoft 365 cloud login details (including session data).

Key findings

  • Proofpoint attributed the activity to a China-aligned group it tracks as TA419.
  • Targets were AI policy experts in US universities, think tanks, and law firms.
  • Lures included invitations to a fake AI policy advisory committee and requests to contribute to a Senate report on AI export controls and supply chains.
  • If a target replied, attackers sent a shortened link that ultimately led to an attacker-controlled domain and an attacker-in-the-middle credential phishing page.
  • The chain used a Cloudflare Turnstile check and a fake OneDrive loading screen before redirecting to the phishing page.
  • Known domains used in the July 2026 campaigns included driftshare[.]co (first stage) and globalfileshareplatform[.]com (second stage).
  • Another lure impersonated a senior Anthropic employee with the subject line “Request for Feedback on Military Integration of Claude.”

Who’s being targeted

  • Commonly targeted roles: University faculty and research staff, Think tank/policy research staff, Legal staff handling export controls / AI policy, Executive assistants supporting policy leaders, IT/helpdesk and identity/access management teams.
  • Affected industries: Higher education (universities), Think tanks / policy research, Legal services (law firms).
  • Attack channels: email, website.
  • Impersonated: AI policy figures (e.g., former White House OSTP leadership), Senior Anthropic employee.

Awareness takeaways

  • Treat unsolicited “committee invitations” and “policy report contributions” as high-risk, and verify the sender via a known, independent channel before replying or clicking anything.
  • Be suspicious of shortened links and file-sharing themed domains; access collaboration documents only through known official portals/bookmarks.
  • Watch for realistic-looking cloud login pages that appear after a “OneDrive loading screen” or web-check step, these can be designed to steal passwords and session cookies.
  • Prioritize phishing-resistant authentication (for example, passkeys) for staff likely to be targeted for cloud-account takeover.

Red flags to watch for

  • Unsolicited invitation to a high-profile committee/report with urgency or prestige framing
  • A shortened URL that resolves to non-official, lookalike file-sharing/cloud domains
  • Login prompt appears behind a “phony OneDrive loading screen” after a web check
  • Unexpected policy request claiming to be from a senior person at a high-profile AI company
  • Email-driven request that pushes the recipient to access “details” via an external link
  • Any Microsoft 365 login prompt reached from a non-Microsoft domain
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get this email: “Join a new AI policy advisory committee” or “Help with a Senate report on AI export controls.” Sounds legit, right? This is how TA419 works: once you reply, they send a shortened link. It hops through driftshare.co, then globalfileshareplatform.com, shows a Cloudflare check and a fake OneDrive loading screen… and lands on a Microsoft 365 login that isn’t really Microsoft. They’ve even spoofed a senior Anthropic employee with the subject line “Request for Feedback on Military Integration of Claude.” The aha: any Microsoft 365 login you reach from a shortened link or a file-sharing domain is a huge red flag. If you get any surprise invite or Claude policy request that leads to a login page, stop and forward it to the security team, don’t click, don’t sign in.

Similar attacks

Fake AI Experts Lure Think Tanks Into M365 Phish

Fake AI Experts Lure Think Tanks Into M365 Phish

A China-aligned group (TA419) targeted US AI policy experts by impersonating well-known AI and policy figures and sending friendly “collaboration” emails. If the target engaged, the attackers redirected them through multiple URLs to a fake Microsoft login pop-up designed to steal Microsoft 365…

October 2, 2026
TA419 Poses as White House to Steal Cloud Logins

TA419 Poses as White House to Steal Cloud Logins

A China-aligned espionage group (TA419) targeted U.S. AI policy experts by impersonating well-known public figures and sending credible policy-related invitations. After victims replied, the attackers sent shortened links that led to a fake OneDrive login designed to capture passwords, MFA codes,…

October 2, 2026
Chinese Spy Phish + Airmen BEC Sentenced

Chinese Spy Phish + Airmen BEC Sentenced

A China-aligned group (TA419) impersonated well-known U.S. figures to lure AI policy experts into a fake OneDrive/Microsoft 365 login that could steal session cookies even when MFA is enabled. Separately, two U.S. airmen were sentenced for a multi-year business email compromise scheme where they…

October 2, 2026
Fake Gmail Attachment Lure Drops Antino Backdoor

Fake Gmail Attachment Lure Drops Antino Backdoor

A China-nexus threat group targeted government and policy organizations across Asia using spear-phishing emails tailored to the victim’s interests. The emails used spoofed trusted senders and a realistic fake Gmail attachment preview that linked to attacker-controlled pages, ultimately installing…

October 2, 2026
China-Linked Phishers Target AI Policy Experts

China-Linked Phishers Target AI Policy Experts

Researchers reported two China-aligned campaigns that used phishing and impersonation to target AI policy experts and multiple Asian government organizations. One campaign built rapport with “AI policy” themed outreach before sending links to a OneDrive credential-harvesting page, while another…

October 1, 2026
Fake AI Advisory Invites Lure US Policy Targets

Fake AI Advisory Invites Lure US Policy Targets

A China-aligned group (tracked as TA419) impersonated real AI policy figures and sent benign-sounding outreach to people working on AI policy at US and Japanese organizations. Once targets replied, the attackers sent a shortened link that ultimately led to a fake OneDrive/Microsoft 365 login page…

October 1, 2026