Oossa

Chinese espionage group used fake AI policy invites to phish US experts

In July 2026 a China‑linked group impersonated Anthropic staff and a former White House official in phishing emails aimed at AI policy makers.

OossaPublished by Oossa: 1 min read

Szabo Viktor · Unsplash

In early July 2026 a suspected Chinese espionage group, tracked as TA419, sent phishing emails that pretended to be from a senior Anthropic employee and a former White House science adviser. The messages asked AI policy experts at US universities, think tanks and law firms to join a bogus AI policy advisory committee or help a Senate report on AI export controls. If a recipient clicked the link, they were taken to a fake OneDrive page that then redirected to a credential‑stealing site.

How the scam worked

The first link in the chain used the domain driftshare.co, which pointed to a Cloudflare‑protected page. That page showed a Cloudflare Turnstile check behind a fake OneDrive loading screen. After the check, the victim was sent to a second domain, globalfileshareplatform.com, that hosted an attacker‑in‑the‑middle (AitM) page. The page captured Microsoft 365/Entra ID login details using open‑source tools that overlay a browser inside the browser. The group also used other file‑sharing‑style domains such as msfile.online and onecloudfilesync.com to hide its activity.

What experts recommend

Proofpoint’s analysis suggests organisations likely to be targeted should adopt phishing‑resistant authentication, such as passkeys that are bound to the original login origin. The group’s domains are hosted behind Cloudflare’s content delivery network, making it harder to trace the servers. TA419 has a history of impersonating other organisations, including the Japan‑Taiwan Exchange Association and the Heritage Foundation.

Why it matters

University researchers, think‑tank analysts and law‑firm consultants could have had their Microsoft 365 accounts compromised, giving attackers access to internal communications and documents. For anyone handling sensitive AI policy work, the episode shows that simple email invitations can be a gateway to credential theft, underscoring the need for stronger login protections. It remains unclear how many accounts were actually compromised, but the tactics suggest future attacks will keep targeting policy influencers.

Was this article useful?
Share

Read next

Oossa · Newsletter

The week in AI, explained

Every Monday: the stories worth knowing, in plain language. Free, no spam.