Protecting organizations from AI-assisted executive impersonation and invoice fraud
Attackers use AI to send fake emails pretending to be CEOs or CFOs. They trick employees into wiring $50,000 to fake bank accounts using fake ServiceNow invoices.
- Report priority
- High
- Targets
- Finance+2 more
How it works
- Attackers use AI tools to create fake emails that look like they come from CEOs or CFOs.
- They send these emails through third-party servers to avoid detection.
- The emails include fake invoices from ServiceNow, asking employees to wire money to attacker-controlled bank accounts.
- The AI helps make the emails look real by adding fake details like company branding and payment instructions.
- Employees who believe the emails may send money without checking further.
What to do
If you work at a US company and recently received an email asking for a wire transfer from a fake executive or invoice, check if it came from a real executive address. Look for suspicious details like fake bank accounts or urgent payment requests. If you're unsure, contact your company's finance or IT team before sending any money.
If you suspect an email is fake, do not reply or click any links. Forward the email to your company's IT or security team for review. Report suspicious emails to your company's fraud department or use your company's phishing reporting tool. Train employees to verify payment requests with the sender directly, especially if they involve large amounts or unusual payment methods.
Technical details
Affected software: Finance, Technology, Targets: United States of America
An employee at a US company receives an email that looks like it came from the CEO. The email includes a fake invoice from ServiceNow, asking for an urgent $50,000 wire transfer to a bank account controlled by the attackers. The email also includes fake email threads between spoofed executives to make it seem legitimate.
This campaign involves AI-assisted executive impersonation and invoice fraud targeting enterprises, primarily US-based organizations. Between August 3, 5, over one million phishing emails were sent via third-party infrastructure, spoofing CEOs and CFOs to request ACH transfers of roughly $50,000. Attackers used AI-generated content to craft convincing fake ServiceNow invoices, including personalized branding, payment instructions, and fabricated email threads between spoofed executives.
Lookalike domains and structured HTML templates with AI-generated comments and labels enhanced legitimacy, reducing recipient skepticism through layered social engineering. The campaign leveraged AI to automate and refine fraudulent communications at scale.