SNACK Summary in 3 Lines
- Campaign scale: more than one million scam emails sent August 3–5, 2026
- Observed reach: 87.7% of messages went to US enterprise users
- Payment lure: nearly $50,000 by ACH through a fabricated annual-subscription invoice
Snackgirls react
Nea — An executive approval, a vendor invoice and a forwarded thread are three props supporting the same story. When everything agrees a little too neatly, I want to inspect the seams.
AIKO — Display names are friendly; sender addresses are evidence. If a payment request asks for secrecy, my social subroutine calls the organization through a number already on file.

Microsoft observed more than one million scam emails sent between August 3 and August 5, 2026, in a campaign that impersonated company executives and sought an Automated Clearing House payment of nearly $50,000 through a fabricated invoice. Microsoft found template characteristics consistent with AI-assisted development, but those indicators do not establish how much of each message was generated by AI.
A fake approval chain built to agree with itself
The attacker combined an executive display name, reply-to identity and signature with a fabricated ServiceNow-branded annual-subscription invoice. A fake forwarded conversation between executives made the expense appear previously discussed and approved, while the payment details led to an attacker-controlled destination. Microsoft observed multiple financial institutions across its samples, so the destination could vary by target.
The campaign relied on attacker-controlled infrastructure, fabricated communications and lookalike domains, including one ServiceNow lookalike registered on July 31 shortly before the emails were sent. Microsoft found no evidence that ServiceNow or the other legitimate organizations named in the lures were compromised or involved.

The story looked polished, but its pieces did not align
Visible warning signs included an executive display name that did not match the sender address, missing normal headers in the supposed forwarded thread and a request not to copy the apparent sender. The thread also contained alignment problems and conflicting claims about who had sent and approved the invoice.
Microsoft identified extensive HTML comments, structured section labels and highly uniform construction as signs consistent with AI-assisted template development. Polished grammar, professional branding or an em dash alone does not prove AI use or fraud; the more useful warning comes from sender, domain, conversation and payment details that conflict with one another.

Verify the request outside the email
CISA advises checking sender addresses and lookalike domains, then contacting the organization through independently known contact information if a request appears suspicious. Do not rely on contact details supplied in the message or on a linked site, and do not send personal or financial information by email. If financial information may have been compromised, contact the financial institution immediately.
For organizational defenses, Microsoft recommends layered controls including email authentication, spoof protection, mail-flow rules, Zero-hour Auto Purge and anti-phishing tools. CISA also recommends enabling anti-phishing features and enforcing multifactor authentication.

Sources and checked date: Microsoft Security Blog · CISA · September 11, 2026
Leave a comment