Security News

China-Linked Hackers Impersonate AI Policy Experts to Steal Microsoft 365 Logins

Infosecurity Magazine · 2 Oct 2026
Key Takeaway Businesses handling sensitive policy, research or defense-related work should move to phishing-resistant sign-in methods like passkeys, since traditional multifactor authentication can be bypassed by these real-time credential relay attacks.

Security researchers at Proofpoint have detailed a credential-theft campaign run by a China-aligned group tracked as TA419, active since at least April 2025. The attackers pose as recognised AI policy experts and economists, including a former White House science and technology official and a senior figure at an AI company, to contact specialists at US and Japanese think tanks, universities, law firms and defense contractors.

The emails start innocently, often inviting the target to join a fake advisory committee or contribute to a report on AI export controls. Victims who reply are sent a link that redirects through several hops to a convincing fake Microsoft login page. This page acts as a real-time relay between the victim and Microsoft's actual login system, meaning passwords, multifactor authentication codes and security checks all pass through successfully. The attackers then capture the resulting session cookies, giving them ongoing access without needing to crack any security controls directly. The group has also built tools to track victims through the login process and extend how long stolen sessions remain valid.

Proofpoint believes the campaign supports intelligence gathering on US AI policy and export control decisions amid ongoing US-China tensions over technology regulation, and expects TA419 to keep impersonating real experts in future attacks.

phishing China-linked threat actor MFA bypass credential theft AI policy

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.