Proofpoint discovered a phishing operation that impersonated ex‑U.S. officials and a staff member of Anthropic to trick AI policy experts into surrendering their Microsoft login credentials.
Proofpoint uncovered a sophisticated phishing campaign that targeted AI policy researchers, using counterfeit identities of former U.S. officials and an employee of Anthropic to harvest Microsoft login credentials.
Campaign Tactics and Deception
The attackers crafted emails that mimicked the tone and formatting of official communications, complete with forged signatures and logos. Recipients were told they needed to verify their accounts to participate in a high‑profile AI policy briefing.
One variant pretended to be a former U.S. diplomat, while another posed as a senior Anthropic researcher. Both messages included a malicious link to a fake Microsoft login page designed to capture usernames and passwords.
Impact on the AI Policy Community
Several AI policy experts reported receiving the fraudulent emails, prompting concerns about the security of sensitive research discussions and the potential for espionage.
If successful, the stolen credentials could grant the threat actors access to internal communications, draft policy documents, and collaboration tools used by government and industry stakeholders.
Mitigation and Recommendations
Proofpoint advises organizations to implement multi‑factor authentication, conduct regular phishing awareness training, and verify the identity of senders through out‑of‑band channels before sharing credentials.
- Enable MFA on all corporate accounts
- Use email authentication protocols such as DMARC, DKIM, and SPF
- Educate staff on recognizing spear‑phishing cues
- Monitor for anomalous login activity
Security teams should also scrutinize any unexpected requests for credential verification, especially when they involve high‑profile individuals or external partners.
NextGov coverage of China‑linked phishing targeting AI experts
Comments
No comments yet.