decrypted · 3 october 2026 · vulnerabilities and patching · ai and llm security

Phishing that beats the second lock: a China-aligned campaign against AI policy experts

A policy analyst receives a courteous email from a senior figure at a leading AI company, asking for views on the military use of its model. According to Proofpoint, reported this week, that is how a China-aligned group it tracks as TA419 went after US experts in AI policy and export controls. The targets were American, and the reports I read name no UK victims. But the technique works on anyone, and the lesson for UK organisations is about design: stop protecting accounts with secrets that a persuasive stranger can talk people into typing.

How the trap worked

The group impersonated a senior Anthropic employee in February. From 8 July it spoofed two named former US officials, a former White House science policy deputy director and a foreign policy economist, inviting recipients to join a fake advisory committee or contribute to a Senate report on AI export controls. Targets were at universities, think tanks and law firms.

Only when someone replied did the link arrive, shortened so it looked innocent. It led through a fake OneDrive loading screen and a Cloudflare Turnstile check, a genuine bot filter that makes a page look more trustworthy. The victim then saw what appeared to be a Chrome sign-in window. It was not a window at all, but a picture of one drawn inside the web page, using an open-source tool called Frameless BitB.

The relay in the middle

Think of a forged bank counter built inside the real bank's lobby. You hand your card and PIN to a convincing clerk, who passes them straight to the real teller, collects what comes back, and keeps a copy. That is an attacker-in-the-middle kit, here using Evilginx phishlets. Proofpoint said it captured passwords, one-time codes and session cookies, accepted the "Keep me signed in" prompt, and submitted codes as soon as they validated.

That is why the usual advice fails. A texted code or an authenticator app feels like a second lock, but the victim types it into the forger's page, which relays it within seconds.

What the defender sees

Very little. The sign-in succeeds, with valid credentials and a valid code. The mail was a plain conversation with no attachment to scan, so controls that hunt for malware have nothing to find. What remains is behavioural: a new session from an unfamiliar location, inbox rules created shortly afterwards, or mailbox access that does not fit the user.

The Secure by Design lesson

Proofpoint's recommendation, as The Register reported it, was phishing-resistant, origin-bound authentication such as passkeys. A passkey is tied to the genuine website address, so a lookalike page cannot ask for it, and the browser will not hand it over. The user's judgement stops being the last line of defence, which is where a design should never leave it.

For a UK director the cost is modest. The real work is enrolment, lost-device support, and the awkward exception list. Start with the people whose inboxes are valuable: board members, finance, legal, policy and anyone handling government or regulatory correspondence. Then disable the weaker fallbacks, because an attacker will simply pick the weakest door left open.

"Multi-factor" is a floor, not a finish line. This is opinion, not advice.

Also this week

FortiMail has an exploited zero-day and no fix yet. Fortinet disclosed CVE-2026-104286, a path traversal flaw rated 9.8, in which an unauthenticated attacker can write files to the appliance through crafted web requests. It is exploited in the wild, and CISA added it to its Known Exploited Vulnerabilities catalogue on 1 October. Fortinet's own product security team identified it. Affected versions run from 7.2.0 to 8.0.1, with fixes planned in 7.4.9, 7.6.7 and 8.0.2 but not yet released. The workaround is to disable the Identity-Based Encryption feature or restrict the management interface to trusted networks. Until fixed versions ship, treat the appliance as exposed, check for unexpected files, and review who can reach the management interface. A mail gateway sees everything, so ask why anything on it faces the internet.

Russian state phishing hit the UK too. Microsoft reports that Star Blizzard ran at least 13 large phishing campaigns between January and August, affecting more than 100 organisations, primarily in the United States and United Kingdom. UK targets included think tanks, NGOs and parliamentary bodies. Lures covered exclusive events, tax audits, payment notices and fines. Its RedFlick technique needs a single user interaction to install a backdoor called CosmicPulse, using scheduled tasks dressed up as legitimate Windows components, which helps it evade detection. For UK policy, charity and academic bodies, the profile fits. Microsoft's advice echoes the lead: phishing-resistant authentication first.

Sources

If you want help putting phishing-resistant sign-in in front of the people who matter, get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.

Play here Loads Apple's player when you press it.