A Fake AI Policy Invite Can Steal a Microsoft 365 Session
Matthew Leo · Published October 2, 2026 · Guides
A believable invitation to advise on AI policy can be more dangerous than an obviously bad phishing email. Proofpoint says a China-aligned group it tracks as TA419 used that approach against people working at US think tanks, universities and law firms.
The first message was deliberately ordinary. It invited a recipient to join an AI policy committee or contribute to work on export controls. The credential-stealing link arrived only after the target replied.
This was an adversary-in-the-middle attack. The fake sign-in page sat between the victim and Microsoft 365, collecting credentials and the authenticated session. That means a familiar MFA prompt was not proof that the page was safe.
Why ordinary MFA may not be enough
Proofpoint’s technical report on TA419 says the campaign used a customized browser-in-the-browser tool and a fake OneDrive page. The attacker’s goal was access to the target’s cloud account.
With this technique, the victim signs in through an attacker-controlled relay. The real service can still send an MFA challenge, but the attacker may capture the resulting session cookie and replay it. Microsoft’s own guidance says traditional MFA can remain vulnerable to adversary-in-the-middle phishing.
Passkeys and FIDO2 security keys are harder to relay because the credential is bound to the legitimate website. Mapletechie’s guide to setting up passkeys without losing recovery access covers the personal-account side of that change. Organizations should also evaluate device-bound token protection and phishing-resistant authentication in Microsoft Entra.
Check the invitation before you follow its link
- Verify the person through another channel: find the organization’s official website and contact the sender using an address or number you locate independently.
- Check the request, not just the name: a real person can be impersonated. Confirm that the committee, report or meeting exists.
- Open cloud services yourself: if a message says a document is in OneDrive, sign in through your saved Microsoft 365 address and look for the shared file there.
- Treat a second email as part of the same test: the TA419 campaign built rapport first. A friendly reply chain does not make a later link safe.
- Escalate unusual policy outreach: think tanks, universities, defence contractors and law firms should give staff a clear path to send suspicious invitations to security teams.
If someone entered credentials
Changing the password is necessary, but it may not end an active stolen session. Microsoft’s session-cookie theft playbook tells administrators to investigate sign-in activity and follow-on changes in Microsoft 365.
The response should include:
- Revoke active sessions and refresh tokens for the affected account.
- Reset the password and confirm that phishing-resistant MFA is registered correctly.
- Review recent sign-ins, devices, mailbox forwarding, inbox rules and permission changes.
- Check whether the same message reached other staff.
- Preserve the original email, headers and URLs for the incident record.
- Review any data the account could access and follow the organization’s breach-notification process if needed.
For a personal Microsoft account, use Microsoft’s official account-security page from a clean device, review recent activity and sign out sessions you do not recognize. Do not return to the link in the original message.
Why Canadian organizations should pay attention
Proofpoint’s disclosed targets were in the United States and Japan, and the report did not identify Canadian victims. The targeting logic still maps closely to Canadian universities, policy institutes, law firms, defence suppliers and public-interest researchers working on AI rules and export controls.
The Canadian Centre for Cyber Security has joined international guidance recommending phishing-resistant MFA for high-value accounts. The practical lesson is simple: protect the identity, not just the password. A realistic invitation, a correct-looking Microsoft page and an MFA prompt can all appear in the same attack.
Tags: Microsoft 365, phishing, TA419, session cookies, cybersecurity