Find notable cyber news and cases, enriched with sources, timelines, and signals.

TA419 AI policy impersonation phishing campaign

Campaign
First reported
Last updated
Happening score
H score 34
1 unique sources, 1 articles

Summary

Hide ▲

The TA419 phishing campaign is still active, using AI policy impersonation to target staff at think tanks, defense contractors, universities and law firms in the US and Japan. The operation has run since at least April 2025 and steers victims to spoofed Microsoft 365/OneDrive login pages that harvest credentials and session cookies. The access pattern supports espionage risk against people working on AI policy and export controls.

Related Happenings

CSuite phishing campaign stealing Microsoft 365 sessions and deploying remote-access tools

Campaign
H score30 First: 30.09.2026 13:45 Last: 30.09.2026 13:45 Sources 1

About this happening: The CSuite phishing campaign is stealing Microsoft 365 sessions and deploying ScreenConnect or Action1, creating paths to account takeover, endpoint control, and b...

Global Profit PhaaS logistics-fraud platform

Threat Actor Meta
H score27 First: 24.09.2026 15:05 Last: 24.09.2026 15:05 Sources 1

About this happening: Global Profit (aka MC Profit Always) is a PhaaS operation tied to a Russian-Armenian threat actor that sells logistics-focused credential theft to other operators. The...

ShinyHunters and Helix passkey-themed Microsoft 365 account compromise campaign

Campaign
H score34 First: 11.09.2026 20:26 Last: 11.09.2026 20:26 Sources 1

About this happening: A ShinyHunters- and Helix-linked campaign is using passkey and SSO-themed social engineering to compromise corporate Microsoft accounts, exposing Microsoft 3...

Anthropic Claude misuse analysis of multi-agent reconnaissance, exploitation, and exfiltration

Technical Analysis
H score59 First: 11.09.2026 17:29 Last: 11.09.2026 17:29 Sources 1

About this happening: Anthropic says Claude AI was abused by multiple threat groups, including ShinyHunters, Midnight Blizzard, and GTG-10007, for credential harvesting, recon...

UNC7005 (Storm-2945) targeted OAuth and WhatsApp phishing campaign

Campaign
H score16 First: 20.08.2026 22:59 Last: 20.08.2026 22:59 Sources 1

About this happening: A UNC7005 (Storm-2945) campaign is hijacking accounts with OAuth, WhatsApp linking, and device-code phishing across academia, diplomatic, nonprofit, and Euro...

Timeline

  1. 01.10.2026 17:00 1 articles · 2h ago

    TA419 sent AI-policy phishing emails posing as Lynne Parker and Heidi Crebo-Rediker

    Exploitation Observed

    TA419 sent emails from July 8 while posing as Lynne Parker and later economist and foreign policy expert Heidi Crebo-Rediker to lure AI policy specialists with a made-up "AI Policy Advisory Committee" invitation and a request to help with a Senate Committee on Foreign Relations report on AI export controls; recipients who replied were pushed through shortened links and redirects to a spoofed OneDrive login page.

    Show sources
  2. 01.10.2026 17:00 2 articles · 2h ago

    Proofpoint details TA419 credential phishing against AI policy specialists at US and Japan institutions

    Initial Disclosure

    Proofpoint's October 1 research said TA419 has run credential phishing against staff at think tanks, defense contractors, universities and law firms in the US and Japan since at least April 2025, using a spoofed Microsoft 365/OneDrive login page built as an adversary-in-the-middle reverse proxy from Frameless BitB to forward Microsoft 365 logins in real time, capture passwords, MFA codes and session cookies, and bypass conditional access checks; Proofpoint assessed the activity as likely supporting Chinese intelligence gathering on US AI policy and advised phishing-resistant sign-in methods such as passkeys and verification through an independent channel.

    Show sources