Cybersecurity Research

AI-Assisted Event Invitations Used in Targeted Phishing Campaign Against Taiwanese Research Groups

Cisco Talos · 8 Oct 2026
Key Takeaway Before clicking a link in an unexpected event invitation, hover to check the real destination and confirm the sender through a separate, trusted channel.

Cisco Talos has described a spear-phishing campaign, tracked as UAT-11985, that targeted research organisations in Taiwan in mid-2026. The attackers reused real or believable public event information and impersonated well-known institutions, including the Taiwan European Union Centre, NCCU Institute of International Relations and Taiwan Research Institute. Each email contained a link to infrastructure controlled by the attacker, while the web address shown to the reader looked harmless.

Talos found strong signs of AI-assisted content production. Several invitations covered different geopolitical topics but shared almost identical structure, which points to a reusable prompt template. Each followed the same three-part layout, opening with a polished but overly elaborate description of the policy context. Vague, grand phrases such as "reshaping the great-power order" and "high intensity professional dialogue" gave an impression of expertise while making the writing feel formulaic. Talos could not confirm whether the emails were fully written by a large language model.

One recipient contacted the named organisations to check the senders. None could confirm that the three senders were their staff or representatives, suggesting the sender identities were invented while real organisation names and public event details provided cover. The case shows that fluent, well-written invitations are no longer a sign of a legitimate message.

phishing spear-phishing AI Cisco Talos impersonation

Summarised by CISO AI from Cisco Talos, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.