As cited
Copy frozen at (site build).
threat intel
Protecting organizations from AI-assisted executive impersonation and invoice fraud
Between August 3 and 5, Microsoft detected a campaign of over one million emails targeting enterprise finance personnel using impersonated executive identities, fabricated ServiceNow invoices, and spoofed email threads to solicit ACH transfers of approximately $50,000. The attack chain included registering lookalike domains, leveraging third-party email services for delivery, and incorporating indicators consistent with artificial intelligence (AI)-assisted template development such as verbose HTML comments and structured formatting. Multiple inconsistencies remained visible to defenders, including misaligned text formatting and suspicious language patterns that deviated from legitimate email conventions.
Why it matters: Finance departments and accounts payable staff at IT services, business advisory, and consumer goods companies are targeted daily by this campaign; practitioners should ensure email authentication (SPF, DKIM, DMARC), AI-detection capabilities, and post-delivery remediation (Zero-hour Auto Purge) are properly configured to block or remove fraudulent payment requests before they reach decision-makers.
- Source published
- First seen by Cybersecurity Tracker