AI-generated CEO fraud campaign hit over a million inboxes
The template quality has improved, but the attack is BEC with a new coat of paint, and the controls that stop it haven't changed.
TL;DR
Microsoft disclosed a campaign that sent more than a million AI-assisted invoice fraud emails between August 3 and 5, impersonating CEOs of targeted companies and directing accounts payable staff to process ACH payments of nearly $50,000. The attacker registered lookalike domains, used third-party email delivery infrastructure, and embedded fabricated ServiceNow invoices alongside faked internal email threads. 87.7% of the emails targeted U.S. recipients. Microsoft found no compromise of the impersonated organizations, including ServiceNow.
The campaign Microsoft's threat research team described this week isn't a new attack class. It's a familiar one (business email compromise dressed up with generative AI) and that's precisely what makes it worth paying attention to.
The attacker registered impersonation domains and used third-party email infrastructure to push out over a million messages in a three-day window. Each email impersonated a CEO and directed accounts payable staff to process a nearly $50,000 ACH transfer. Below the executive's "approval" sat a forwarded thread between the fake CEO and a fake ServiceNow representative, followed by a fabricated invoice. Multiple companies were targeted; Microsoft said the impersonated organizations, including ServiceNow, were not compromised.
Microsoft flagged several indicators consistent with generative AI use during template creation. The language was fluid and grammatically clean across a mass campaign, the kind of variability that historically required a human to produce. The attacker incorporated multiple techniques within each email to build a unified narrative: executive impersonation, vendor branding, fabricated invoices, and fake internal conversations all layered together.
The distribution data tells the familiar BEC story. 87.7% of emails went to U.S. recipients. The campaign was concentrated against enterprise users, and Microsoft's detection guidance (flagging reply-to mismatches, inspecting domain registration age, and monitoring for impersonation signals) largely restates existing Defender capabilities.
That's the point. AI didn't invent the attack; it lowered the production cost and raised the polish. The templates read naturally, varied across targets, and avoided the grammatical tells that used to trip scams at the spam filter. For the accounts payable clerk who's seen a hundred crude lures, the difference matters. But the detection surface hasn't shifted. Impersonation domains still get registered. Reply-to addresses still diverge from senders. Finance staff still get asked to wire money on a CEO's say-so.
The wrapper is new. The controls are not. That's the takeaway worth briefing the AP team on.
Published ·Deep Fathom