www.darkreading.com 11 Sept 2026, 19:21 UTC

AI Phishing Campaign Targets Finance Teams With 1 Million Emails

CyberSIXT Evidence Panel Source marked as original reporting

CYBERCRIMINALS have demonstrated a new capability in fraud campaigns by using AI to generate and deliver personalised mass phishing. In a campaign tracked by Microsoft researchers, an unattributed threat actor sent more than one million emails in just three days, targeting organisations’ accounts payable teams.

The messages were lightly personalised with real names of targeted executives and included forged invoice detail aimed at a near-$50,000 balance owed to an impersonated enterprise cloud services company, ServiceNow. The emails were framed as an authentic email thread, depicting a conversation between an executive and the president of ServiceNow, designed to prompt the recipient to forward the invoice to the finance department.

Evidence from the reporting notes that attackers leveraged AI to gather public information about organisations and to generate convincing content and templates at scale. In practice, the operation involved identifying chief executive signatures and embedding them into the phishing messages to enhance credibility. The campaign reached organisations across multiple sectors, with IT, consumer goods, and real estate being common targets, and about 87.7% of targets located in the United States.

Experts emphasise that AI is accelerating traditional phishing and impersonation techniques rather than introducing wholly new threats; the core defence remains layered security, including authentication, spoof protection, email security filters, and human awareness, augmented by AI-powered detection and response.

The article quotes industry observers on how the “industrialisation” of effective phishing campaigns poses risk, and notes that standard controls can still detect malicious indicators, even as attackers increasingly use AI to scale and personalise attacks.

View full article

Article by CyberSIXT