China-Linked Hackers Impersonate AI Policy Experts to Steal Microsoft 365 Logins
Security researchers at Proofpoint have detailed a credential-theft campaign run by a China-aligned group tracked as TA419, active since at least April 2025. The attackers pose as recognised AI policy experts and economists, including a former White House science and technology official and a senior figure at an AI company, to contact specialists at US and Japanese think tanks, universities, law firms and defense contractors.
The emails start innocently, often inviting the target to join a fake advisory committee or contribute to a report on AI export controls. Victims who reply are sent a link that redirects through several hops to a convincing fake Microsoft login page. This page acts as a real-time relay between the victim and Microsoft's actual login system, meaning passwords, multifactor authentication codes and security checks all pass through successfully. The attackers then capture the resulting session cookies, giving them ongoing access without needing to crack any security controls directly. The group has also built tools to track victims through the login process and extend how long stolen sessions remain valid.
Proofpoint believes the campaign supports intelligence gathering on US AI policy and export control decisions amid ongoing US-China tensions over technology regulation, and expects TA419 to keep impersonating real experts in future attacks.