Raw data, clear context.

[
[
[

]
]
]

Microsoft says it observed more than one million fraudulent emails in a campaign that impersonated executives and ServiceNow, attached fabricated invoices and sought ACH payments near $50,000. The company found no evidence that the legitimate organisations named in the lures were compromised. It saw signs consistent with AI-assisted template development, but says those signs do not prove how much content AI generated.[1][2]

Editorial infographic about Microsoft reporting on a payment scam. It shows more than 1 million messages, 87.7 percent of campaign messages sent to users in the United States, and requested ACH payments of nearly 50,000 dollars. The lure used executive impersonation, lookalike domains, ServiceNow branding, a fabricated invoice and a staged forwarded thread. The defensive control is verification through a known contact route, stored vendor details and normal dual approval. AI-assisted template development is possible but not proven. The graphic notes that message volume is not a count of successful payments or unique victims.
Microsoft’s observed campaign combined executive impersonation, vendor branding, a fabricated invoice and a staged email thread. This editorial synthesis separates reported lure components from the independent payment verification control; it does not show successful payments or prove the extent of AI generation.

An old payment scam with more layers

The campaign described by Microsoft was a business email compromise operation. Its objective was straightforward: persuade a finance employee that a payment had already been approved by a senior executive and supported by a trusted supplier.[1] The novelty was in the construction of the lure, which combined several pieces of borrowed authority instead of relying on a single suspicious request.[1][2]

The messages used the names of CEOs, CFOs or presidents in the sender display name, Reply-To display name and signature. They included a short approval for an invoice, then placed a fabricated ServiceNow subscription invoice below it.[1] A further block of fake forwarded messages supplied a conversation about the purchase and its implementation.[1][2]

The invoice was not issued by ServiceNow. Microsoft says the actor used attacker-controlled infrastructure, fabricated communications and lookalike domains, and found no evidence that the legitimate organisations referenced in the lures, including ServiceNow, were compromised or involved.[1]

The observed attack chain

Microsoft’s account can be reduced to four linked stages:

  • Preparation: domains resembling a supplier and a separate Reply-To domain were registered shortly before the campaign.[1]
  • Delivery: several third-party email-service accounts sent more than one million messages to enterprise users between 3 and 5 August.[1]
  • Impersonation: the messages combined a senior executive, ServiceNow branding, a fabricated invoice and a staged email thread.[1][2]
  • Payment request: accounts-payable teams were urged to initiate an ACH payment of nearly $50,000.[1][2]

This sequence is an editorial synthesis of the documented elements, not a claim that Microsoft traced a successful payment through every stage. The sources reviewed do not provide a victim-by-victim outcome dataset.[1][2]

Where the AI claim stops

Microsoft identified extensive HTML comments, structured section labels and highly uniform template construction. The company says these indicators are consistent with generative-AI involvement, while also stating that they cannot independently establish the extent to which AI generated the campaign content.[1]

The Record, in a secondary report of Microsoft’s account, reported the same boundary. Its account describes the campaign as an established BEC pattern made more tailored and layered, rather than as a new category of attack.[2] That distinction matters: the evidence supports possible AI assistance in preparing reusable templates, but it does not identify a model, operator, prompt, generation workflow or proportion of text produced by a model.[1][2]

The scale is also easy to misread. More than one million messages is a delivery count, not a count of successful compromises, payments or unique victims. Neither Microsoft nor The Record states a conversion rate for the campaign.[1][2]

The control point is outside the email

Microsoft recommends layered email and endpoint controls, including authentication, spoof protection, mail-flow rules and post-delivery removal through Zero-hour Auto Purge.[1] Those measures can reduce delivery and speed containment, but the payment decision needs a separate control.

A message can contain convincing branding and still fail a basic business test. Read0nly’s defensive synthesis is to verify an unfamiliar payment request through a known contact route, use the supplier record already held by the organisation and require the normal approval path. A request to bypass dual approval, change a beneficiary or keep the executive out of the reply chain should be treated as a stop condition.[1][3]

Email authentication is useful evidence, not proof that the invoice is genuine. Suped’s technical review notes that DMARC tests alignment between the visible From domain and an authenticated domain; it does not validate a display name, Reply-To ownership, invoice truth or payment authority. The source also notes that this campaign record does not establish whether the messages passed or failed an authentication check, so full headers would be needed before drawing that conclusion.[3]

That separation is the practical lesson from the campaign. Mail systems assess whether a message is technically consistent with a domain. Finance processes assess whether a person is authorised to request a payment and whether the beneficiary is legitimate. Treating either check as a substitute for the other leaves the most valuable decision exposed.

What remains to be established

The public record supports a detailed account of the campaign’s construction and intended payment route. It does not establish the identity of the operator, the total financial loss, the number of successful transfers or the exact role played by generative AI.[1][2]

For defenders, the actionable boundary is narrower than the headline. Detect the combined pattern of executive impersonation, vendor branding, lookalike domains, fabricated invoice material and payment urgency. Then make the final transfer depend on a verification path that the email itself cannot control.[1][2][3]

Sources

[1] Protecting organizations from AI-assisted executive impersonation and invoice fraud | Microsoft Security Blog

[2] Microsoft sees some new wrinkles in invoice-scam emails | The Record

[3] Microsoft uncovers million-email executive impersonation campaign | Suped