Protecting organizations from AI-assisted executive impersonation and invoice fraud

Published September 10, 2026

Attackers use AI to make fake emails look like real messages from CEOs, tricking finance teams into sending $50,000 payments. Microsoft warns of a million-sent scam campaign using AI-generated fake threads and invoices.

Report priority
Medium

How it works

  • Attackers register fake domains to send emails that look like real messages from CEOs.
  • They use AI to create convincing fake email threads and invoices.
  • The emails include fake details like ACH payment requests and forwarded messages.
  • Finance teams see these as real requests and process payments without checking.
  • This lets attackers steal money from companies.

What to do

If you work in finance or accounts payable and received an email from your CEO's address asking for a payment, check if it includes a forwarded email thread or invoice. If the email looks suspicious or includes unexpected details, do not process the payment. Contact your company's IT or security team to verify the request.

Train your finance team to verify unusual payment requests, even if they look like they come from a CEO. Use Microsoft Defender or similar tools to detect fake emails. Report suspicious emails to your IT or security team immediately. Do not reply or click links in unexpected emails.

Technical details

Attackers sent over a million fake emails impersonating CEOs. Each email included a fake invoice and a fabricated email thread to make it look real. Finance teams at the target companies processed ACH payments of nearly $50,000 based on these fake requests.

A threat actor deployed an AI-assisted executive impersonation campaign between August 3 and 5, sending over one million fraudulent emails to trick finance teams into processing unauthorized ACH payments. The attack impersonated CEOs and included fabricated email threads and invoices to mimic legitimate internal communications, targeting accounts payable departments with requests for nearly $50,000 transfers. Attackers registered impersonation domains, used third-party email delivery infrastructure, and embedded forged conversations with a spoofed ServiceNow account to enhance credibility. The campaign primarily targeted U.S. enterprises, leveraging AI-generated templates to personalize and refine the deception.