www.microsoft.com 10 Sept 2026, 17:23 UTC

AI-Assisted Invoice Scam Impersonates CEOs to Steal $50,000 Payments

AI-Assisted Invoice Scam Impersonates CEOs to Steal $50,000 Payments
CyberSIXT Evidence Panel Source marked as original reporting

THREAT actors are increasingly using AI-assisted techniques to impersonate executives and target accounts payable teams with invoice fraud. Microsoft’s analysis describes a recent campaign in which attackers registered lookalike domains, used third‑party email infrastructure to deliver over a million messages, and posed as CEOs to push for an ACH transfer of about $50,000.

The attackers augmented the narrative with a fabricated invoice, a forwarded email thread, and branding that mimicked legitimate organisations, including ServiceNow, to add credibility. While the spoofed ServiceNow references were part of the fraud, Microsoft found no evidence that the real entity was compromised; the operation relied on attacker‑controlled domains and content designed to resemble trusted brands.

The campaign’s attack chain involved email delivery, domain registration, and the use of generative AI cues to create convincing templates. Indicators of AI involvement included extensive HTML comments, highly uniform template construction, and distinctive formatting that suggested template generation, though these alone do not prove the extent of AI authorship.

Defenders can glean practical signals from the spoofed headers, inconsistent thread formatting, and the presence of invoicing details that urge payment via bank transfer to attacker‑controlled accounts. Microsoft details mitigations centred on layered protections: strict email authentication, spoof protection, and post‑delivery controls via Defender for Office 365, alongside Defender XDR and Security Copilot for investigation and response.

They also recommend enabling automatic attack disruption and Zero‑hour Auto Purge, plus anti‑phishing and web‑protection measures to curb such social‑engineering campaigns before payments are made.

View full article

Article by CyberSIXT