Microsoft traces more than one million executive-impersonation emails

SNACK Summary in 3 Lines

  • Campaign scale: more than one million scam emails sent August 3–5, 2026
  • Observed reach: 87.7% of messages went to US enterprise users
  • Payment lure: nearly $50,000 by ACH through a fabricated annual-subscription invoice

Snackgirls react

Nea — An executive approval, a vendor invoice and a forwarded thread are three props supporting the same story. When everything agrees a little too neatly, I want to inspect the seams.

AIKO — Display names are friendly; sender addresses are evidence. If a payment request asks for secrecy, my social subroutine calls the organization through a number already on file.

Microsoft diagram of the executive impersonation and invoice fraud attack chain
Image source: Microsoft — attack chain from domain registration to executive impersonation, a fabricated invoice and attempted payment

Microsoft observed more than one million scam emails sent between August 3 and August 5, 2026, in a campaign that impersonated company executives and sought an Automated Clearing House payment of nearly $50,000 through a fabricated invoice. Microsoft found template characteristics consistent with AI-assisted development, but those indicators do not establish how much of each message was generated by AI.

A fake approval chain built to agree with itself

The attacker combined an executive display name, reply-to identity and signature with a fabricated ServiceNow-branded annual-subscription invoice. A fake forwarded conversation between executives made the expense appear previously discussed and approved, while the payment details led to an attacker-controlled destination. Microsoft observed multiple financial institutions across its samples, so the destination could vary by target.

The campaign relied on attacker-controlled infrastructure, fabricated communications and lookalike domains, including one ServiceNow lookalike registered on July 31 shortly before the emails were sent. Microsoft found no evidence that ServiceNow or the other legitimate organizations named in the lures were compromised or involved.

Microsoft chart showing industries targeted by the invoice fraud email campaign
Image source: Microsoft — industry distribution in the campaign that sent more than one million scam emails

The story looked polished, but its pieces did not align

Visible warning signs included an executive display name that did not match the sender address, missing normal headers in the supposed forwarded thread and a request not to copy the apparent sender. The thread also contained alignment problems and conflicting claims about who had sent and approved the invoice.

Microsoft identified extensive HTML comments, structured section labels and highly uniform construction as signs consistent with AI-assisted template development. Polished grammar, professional branding or an em dash alone does not prove AI use or fraud; the more useful warning comes from sender, domain, conversation and payment details that conflict with one another.

Microsoft example of an email that impersonates a company executive to approve an invoice
Image source: Microsoft — example email impersonating a company executive to approve an invoice

Verify the request outside the email

CISA advises checking sender addresses and lookalike domains, then contacting the organization through independently known contact information if a request appears suspicious. Do not rely on contact details supplied in the message or on a linked site, and do not send personal or financial information by email. If financial information may have been compromised, contact the financial institution immediately.

For organizational defenses, Microsoft recommends layered controls including email authentication, spoof protection, mail-flow rules, Zero-hour Auto Purge and anti-phishing tools. CISA also recommends enabling anti-phishing features and enforcing multifactor authentication.

Microsoft example of the fabricated ServiceNow-branded invoice used in the campaign
Image source: Microsoft — attacker-created invoice impersonating ServiceNow

Sources and checked date: Microsoft Security Blog · CISA · September 11, 2026

Related hashtags
#GameSunakku #Microsoft #Cybersecurity #Phishing #InvoiceFraud #EmailSecurity #AI

Comments

Leave a comment

Game Sunakku에서 더 알아보기

지금 구독하여 계속 읽고 전체 아카이브에 액세스하세요.

계속 읽기