A Fake AI Policy Invite Can Steal a Microsoft 365 Session

Matthew Leo · Published October 2, 2026 · Guides

A policy researcher reviews an email on a laptop while taking notes at a sunlit office desk.

A believable invitation to advise on AI policy can be more dangerous than an obviously bad phishing email. Proofpoint says a China-aligned group it tracks as TA419 used that approach against people working at US think tanks, universities and law firms.

The first message was deliberately ordinary. It invited a recipient to join an AI policy committee or contribute to work on export controls. The credential-stealing link arrived only after the target replied.

This was an adversary-in-the-middle attack. The fake sign-in page sat between the victim and Microsoft 365, collecting credentials and the authenticated session. That means a familiar MFA prompt was not proof that the page was safe.

Why ordinary MFA may not be enough

Proofpoint’s technical report on TA419 says the campaign used a customized browser-in-the-browser tool and a fake OneDrive page. The attacker’s goal was access to the target’s cloud account.

With this technique, the victim signs in through an attacker-controlled relay. The real service can still send an MFA challenge, but the attacker may capture the resulting session cookie and replay it. Microsoft’s own guidance says traditional MFA can remain vulnerable to adversary-in-the-middle phishing.

Passkeys and FIDO2 security keys are harder to relay because the credential is bound to the legitimate website. Mapletechie’s guide to setting up passkeys without losing recovery access covers the personal-account side of that change. Organizations should also evaluate device-bound token protection and phishing-resistant authentication in Microsoft Entra.

Check the invitation before you follow its link

If someone entered credentials

Changing the password is necessary, but it may not end an active stolen session. Microsoft’s session-cookie theft playbook tells administrators to investigate sign-in activity and follow-on changes in Microsoft 365.

The response should include:

For a personal Microsoft account, use Microsoft’s official account-security page from a clean device, review recent activity and sign out sessions you do not recognize. Do not return to the link in the original message.

Why Canadian organizations should pay attention

Proofpoint’s disclosed targets were in the United States and Japan, and the report did not identify Canadian victims. The targeting logic still maps closely to Canadian universities, policy institutes, law firms, defence suppliers and public-interest researchers working on AI rules and export controls.

The Canadian Centre for Cyber Security has joined international guidance recommending phishing-resistant MFA for high-value accounts. The practical lesson is simple: protect the identity, not just the password. A realistic invitation, a correct-looking Microsoft page and an MFA prompt can all appear in the same attack.

Tags: Microsoft 365, phishing, TA419, session cookies, cybersecurity

Read on Mapletechie