Microsoft has uncovered a large-scale email fraud campaign using executive impersonation, fabricated invoices and indicators of Generative AI-assisted content creation to target finance teams.
Microsoft has warned organisations about a large-scale business email compromise campaign in which attackers impersonated company executives and attempted to convince finance teams to make fraudulent payments of almost US$50,000.
Between August 3 and 5, Microsoft detected more than one million emails targeting enterprise users, with 87.7% of the campaign directed at users in the US.
The attackers used third-party email delivery infrastructure and impersonated senior executives including CEOs, CFOs and company presidents. The fraudulent identities appeared in sender display names, reply-to information and email signatures.
Rather than relying on a single social engineering lure, the campaign combined executive impersonation with vendor branding, fabricated invoices and fake forwarded email conversations to create a more convincing narrative.
In examples analysed by Microsoft, attackers impersonated ServiceNow and included a professional-looking fraudulent invoice for an annual platform subscription. The invoices contained branding, payment information and personalised details relating to the targeted company and executive.
Recipients were instructed to make bank transfers to accounts controlled by the attackers.
Microsoft stressed that it found no evidence that ServiceNow or the other legitimate organisations impersonated during the campaign had been compromised or were involved in the activity.
Researchers also identified several indicators consistent with Generative AI being used to help develop the email templates, including extensive HTML comments, structured section labelling and highly uniform template construction.
Microsoft cautioned, however, that these indicators do not independently establish the extent to which AI generated the campaign’s content.
The attackers also registered lookalike domains shortly before launching the campaign, including one designed to impersonate ServiceNow.
Microsoft said the campaign demonstrates how AI could help attackers improve established social engineering techniques by producing more tailored and convincing communications.
The company recommends organisations strengthen email authentication and anti-phishing controls while ensuring suspicious payment requests involving executives or suppliers are independently verified.


