Skip to content
Auto-CTI
Back to all deep dives
MICROSOFT SECURITY BLOG

Protecting organizations from AI-assisted executive impersonation and invoice fraud

HIGH executive-impersonation invoice-fraud AI-driven-phishing email-authentication

Strategic summary

Microsoft observed a campaign of over one million fraudulent emails using generative AI to impersonate executives and commit invoice fraud. The attackers impersonated CEOs to convince accounts payable departments to process ACH transfers of nearly USD 50,000, using fabricated email threads and invoices. The emails were sent via third-party infrastructure, mostly to users in the United States. Microsoft found no evidence that legitimate organizations, including ServiceNow, were compromised.

Key findings

  • Over one million emails were sent between August 3 and 5 through multiple third-party accounts, with 87.7 percent targeting recipients in the United States.
  • The attackers impersonated CEOs in display name, reply-to address, and signature, requesting ACH payments of nearly USD 50,000.
  • Forwarded email threads and fabricated invoices between the CEO and ServiceNow were included to increase credibility.
  • The campaign combined executive impersonation, vendor branding, fabricated invoices, and supporting conversations.
  • There is no evidence of compromise of legitimate organizations, including ServiceNow.

Relevance for you

Threat actors are leveraging AI-powered techniques to craft highly convincing spoofed emails impersonating internal executives, enabling large-scale campaigns distributing over one million fraudulent messages.

Risk score

20
cvss base
0.00
kev bonus
0.00
epss bonus
0.00
poc bonus
0.00
raw before weight
0.00
industry weight
1.10
freshness factor
1.00
exploitability factor
1.00
days old
0.00
vendor mismatch penalty
0.00

Path: operational

ESC