CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Protecting organizations from AI-assisted executive impersonation and invoice fraud

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7033

As cited

Copy frozen at (site build).

threat intel

Protecting organizations from AI-assisted executive impersonation and invoice fraud

Between August 3 and 5, Microsoft detected a campaign of over one million emails targeting enterprise finance personnel using impersonated executive identities, fabricated ServiceNow invoices, and spoofed email threads to solicit ACH transfers of approximately $50,000. The attack chain included registering lookalike domains, leveraging third-party email services for delivery, and incorporating indicators consistent with artificial intelligence (AI)-assisted template development such as verbose HTML comments and structured formatting. Multiple inconsistencies remained visible to defenders, including misaligned text formatting and suspicious language patterns that deviated from legitimate email conventions.

Why it matters: Finance departments and accounts payable staff at IT services, business advisory, and consumer goods companies are targeted daily by this campaign; practitioners should ensure email authentication (SPF, DKIM, DMARC), AI-detection capabilities, and post-delivery remediation (Zero-hour Auto Purge) are properly configured to block or remove fraudulent payment requests before they reach decision-makers.

VendorsMicrosoftServiceNow
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary