Fake AI Experts Lure Think Tanks Into M365 Phish

IT Pro Security · High sophistication
Last updated October 2, 2026

A China-aligned group (TA419) targeted US AI policy experts by impersonating well-known AI and policy figures and sending friendly “collaboration” emails. If the target engaged, the attackers redirected them through multiple URLs to a fake Microsoft login pop-up designed to steal Microsoft 365 passwords, MFA codes, and session cookies.

Key findings

  • TA419 impersonated real people (including US government and AI-company-linked identities) to build credibility with AI policy targets.
  • Initial outreach used benign-sounding collaboration lures such as joining an “AI Policy Advisory Committee.”
  • Victims who responded were sent through a multi-stage redirection chain into an Adversary-in-the-Middle credential phishing flow.
  • The attack used a Browser-in-the-Browser technique (Frameless BitB) to show a fake Microsoft login pop-up over a OneDrive-like page.
  • The phishing flow relayed credentials to real Microsoft infrastructure to steal Microsoft 365 passwords, MFA codes, and session cookies.
  • Cloudflare CDN was used to help obscure backend hosting, and domains were mostly registered via NameSilo.

Who’s being targeted

  • Commonly targeted roles: Think tank staff, AI policy teams, University researchers, Legal and regulatory teams, Executives working on AI strategy/policy.
  • Affected industries: Think tanks, Universities, Law firms, Defense contractors.
  • Attack channels: email, website.
  • Impersonated: A real AI policy/US government subject-matter expert (e.g., former White House OSTP leadership member), A senior employee of Anthropic.

Awareness takeaways

  • Treat unsolicited “collaboration” requests, especially from famous experts or executives, as high-risk and verify via a separate, known-good contact method.
  • Be suspicious of document-sharing pages that display a pop-up Microsoft login window; go to Microsoft 365 directly instead of signing in via an embedded prompt.
  • Understand that attackers may capture more than a password; entering MFA codes into a phishing site can still compromise your account.
  • For higher-risk teams (policy, executive, research), consider phishing-resistant authentication such as passkeys.

Red flags to watch for

  • Unsolicited collaboration request using a high-profile person's identity
  • Unexpected sign-in prompt presented as a pop-up over a document-sharing page
  • Link redirects through multiple steps before reaching the login screen
  • Unexpected outreach about sensitive AI/military topics from someone you have not previously worked with
  • Pressure to review content via a link that requires a Microsoft login
  • Login prompt appears as an embedded/overlay window rather than a normal sign-in page
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email from a former White House AI advisor inviting you to an “AI Policy Advisory Committee.” Sounds flattering, right? If you reply, they send a link. It bounces through a few URLs, lands on a OneDrive-looking page, and then, here’s the trick, a fake Microsoft login pops up inside the page. That’s a Browser-in-the-Browser, or BitB, stealing your Microsoft 365 password, MFA code, and even session cookies. They’ve done this while impersonating US government AI leaders and even a senior Anthropic employee asking for feedback on the military integration of Claude. The red flags: you didn’t expect this outreach, the link hops around, and the Microsoft sign-in appears as a pop-up over a document page instead of a normal login tab. Here’s your move: any time a collab email sends you to a pop-up Microsoft login over a OneDrive-style page, close it and go sign in at office.com or outlook.com yourself instead.

Similar attacks

TA419 Poses as White House to Steal Cloud Logins

TA419 Poses as White House to Steal Cloud Logins

A China-aligned espionage group (TA419) targeted U.S. AI policy experts by impersonating well-known public figures and sending credible policy-related invitations. After victims replied, the attackers sent shortened links that led to a fake OneDrive login designed to capture passwords, MFA codes,…

October 2, 2026
Fake AI Advisory Invites Steal M365 Logins

Fake AI Advisory Invites Steal M365 Logins

Researchers say a China-aligned group (TA419) impersonated well-known AI policy figures and an Anthropic executive to lure US AI policy experts into replying to emails about a fake advisory committee or Senate report. Once a target engaged, the attackers sent shortened links that led through a fake…

October 1, 2026
Chinese Spy Phish + Airmen BEC Sentenced

Chinese Spy Phish + Airmen BEC Sentenced

A China-aligned group (TA419) impersonated well-known U.S. figures to lure AI policy experts into a fake OneDrive/Microsoft 365 login that could steal session cookies even when MFA is enabled. Separately, two U.S. airmen were sentenced for a multi-year business email compromise scheme where they…

October 2, 2026
China-Linked TA419 Phishes US AI Policy Experts

China-Linked TA419 Phishes US AI Policy Experts

Proofpoint linked China-nexus actor TA419 to credential-phishing campaigns aimed at U.S. AI policy experts, including people at think tanks. The attacker impersonated well-known AI policymakers and an Anthropic executive, using believable “advisory committee” and “research questions” emails to draw…

October 2, 2026
Fake AI Advisory Invites Lure US Policy Targets

Fake AI Advisory Invites Lure US Policy Targets

A China-aligned group (tracked as TA419) impersonated real AI policy figures and sent benign-sounding outreach to people working on AI policy at US and Japanese organizations. Once targets replied, the attackers sent a shortened link that ultimately led to a fake OneDrive/Microsoft 365 login page…

October 1, 2026
Fake ChatGPT Invoice Email Steals Logins

Fake ChatGPT Invoice Email Steals Logins

Attackers are sending fake ChatGPT billing emails that pressure people to “update payment” within 48 hours to avoid service interruption. The message links to a convincing look‑alike ChatGPT login page via a Google redirect, aiming to steal OpenAI credentials.

September 18, 2026