Proofpoint says China-aligned TA419 has posed as a former White House official and an Anthropic employee to phish AI policy experts since at least April 2025. The first approach asks for nothing; the credential-stealing link follows only after a target replies.
Perspective Coverage
7 publishers
- Builder
- Builder 28%
- Operator
- Operator 59%
- Investor
- Investor 13%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+20
- Incentives30
- Confidence65
Proofpoint says China-aligned TA419 has phished US AI policy experts since April 2025 with a proxy that captures Microsoft session cookies and bypasses MFA. Its fix is passkeys plus out-of-band checks on unsolicited expert outreach.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence50
Microsoft's 2026 Digital Defense Report puts MFA-relaying proxy kits at 44.6% of phishing techniques, as phishing rose to 23% of its incident cases. SMS codes and push approvals pass straight through those proxies, so protecting company email now means passkeys or FIDO2 keys, starting with admins and finance staff.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+5
- Incentives40
- Confidence55
FIDO's export format for passkeys has only begun shipping in iOS 26 and Android, with the FIDO Alliance counting 5 billion passkeys in use. The key that makes them phishing-resistant cannot be copied off the device, so adopters need a plan for lost devices and changed managers.
Reality
- Evidence55
- Adoption65
- Hype gap+10
- Incentives
- Insufficient
- Confidence55
ShinyHunters has shown journalists FBI medical exams that name agents and their addresses, from a set it says covers about 60,000 current and former staff. The FBI has so far confirmed only an incident in FBIJobs-related systems, and the group is threatening to publish within five days.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives60
- Confidence45
CloudSEK took administrator access to the panel and counted 5,137 stolen records coming off 42 VPS nodes into five leasing affiliates' Telegram bots, with the phishing pages dark for three weeks while the panel itself stays reachable.
Perspective Coverage
3 publishers
- Builder
- Builder 30%
- Operator
- Operator 60%
- Investor
- Investor 10%
Reality
- Evidence55
- Adoption30
- Hype gap+25
- Incentives40
- Confidence60
Calendar, People and Files stop working on December 16, 2026, and Microsoft has already stopped shipping them, leaving a removal job on fleets that took the apps automatically at the end of 2025.
Reality
- Evidence74
- Adoption46
- Hype gap+20
- Incentives58
- Confidence71
CloudSEK got inside the BigBear 2.0 administrative panel and found more captured Microsoft 365 session cookies than plaintext passwords, along with code written to switch FIDO2 off on the phishing pages.
Reality
- Evidence55
- Adoption58
- Hype gap+12
- Incentives72
- Confidence56
Island's write-up describes an adversary-in-the-middle proxy that hands passwords, push approvals and SMS codes to real Microsoft servers, then keeps the cookie Microsoft issues. Origin binding is the only listed control that breaks it.
Reality
- Evidence48
- Adoption40
- Hype gap+18
- Incentives66
- Confidence47
Island says the kit relays Microsoft 365 sign-ins behind genuine Docusign envelopes and legitimate Microsoft or Google redirects, leaving sender reputation nothing to grade.
Reality
- Evidence60
- Adoption58
- Hype gap+18
- Incentives74
- Confidence62
Okta Threat Intelligence says as-a-service phishing kits now let a caller change what the target sees in real time, synced to genuine MFA prompts. Push and OTP were not built to survive that.
Publishers:okta.com
Reality
- Evidence46
- Adoption28
- Hype gap+22
- Incentives78
- Confidence44