← Back to feed
Threat Actors & CampaignsEmerging2 sourcesSep 10, 2026 · 17:23via Microsoft Security Blog

Protecting organizations from AI-assisted executive impersonation and invoice fraud

Brief

In this article

  • Attack chain overview
  • Email Delivery
  • Domain registration
  • Generative AI usage
  • Mitigation and protection guidance
  • Microsoft Defender detections
  • Microsoft Security Copilot
  • Threat intelligence reports
  • MITRE ATT&CK Techniques observed
  • Indicators of compromise (IOC)
  • Learn More

Threat actors are increasingly improving their tactics to make suspicious emails look like legitimate email notifications to potential victims, deploying techniques that impersonate internally sent emails from executive team members. While this technique is not new, the adoption of AI has enabled threat actors to improve their campaign templates and construct emails tailored to their recipients.

Additionally, threat actors are incorporating multiple techniques within the same email to improve the overall narrative further.

Read more on Microsoft Security Blog→

All credited sources

Highest-trust first. Dates are the publisher's original publish time.

Microsoft Security BlogPrimary··trust 1.36

Protecting organizations from AI-assisted executive impersonation and invoice fraud

In this article

  • Attack chain overview
  • Email Delivery
  • Domain registration
  • Generative AI usage
  • Mitigation and protection guidance
  • Microsoft Defender detections
  • Microsoft Security Copilot
  • Threat intelligence reports
  • MITRE ATT&CK Techniques observed
  • Indicators of compromise (IOC)
  • Learn More

Threat actors are increasingly improving their tactics to make suspicious emails look like legitimate email notifications to potential victims, deploying techniques that impersonate internally sent emails from executive team members. While this technique is not new, the adoption of AI has enabled threat actors to improve their campaign templates and construct emails tailored to their recipients.

Additionally, threat actors are incorporating multiple techniques within the same email to improve the overall narrative further.

In this blog, we will discuss a recent campaign observed using third-party email delivery infrastructure to send out over a million financial fraud scam emails that displayed multiple indicators consistent with the use of generative AI during email template creation.

The threat actor impersonated CEOs of multiple target companies, attempting to convince accounts payable departments of the same companies to process an Automated Clearing House (ACH) payment of nearly $50,000. To add legitimacy, the actor included a forwarded email thread (and a fabricated invoice) between the impersonated CEO and ServiceNow (which was also being impersonated).

Attack chain overview

The campaign follows steps before and during the execution of the campaign: threat actors register impersonation domains, send executive-themed payment requests through trusted infrastructure, embed fabricated invoices and supporting conversations, and attempt to convince finance personnel to initiate ACH transfers.

Figure 1: Attack chain showing domain registration, executive impersonation, invoice fraud delivery, ACH payment execution, and financial theft.

Read more →
Malware.news··trust 0.88

Protecting organizations from AI-assisted executive impersonation and invoice fraud

In this article

  • Attack chain overview
  • Email Delivery
  • Domain registration
  • Generative AI usage
  • Mitigation and protection guidance
  • Microsoft Defender detections
  • Microsoft Security Copilot
  • Threat intelligence reports
  • MITRE ATT&CK Techniques observed
  • Indicators of compromise (IOC)
  • Learn More

Threat actors are increasingly improving their tactics to make suspicious emails look like legitimate email notifications to potential victims, deploying techniques that impersonate internally sent emails from executive team members. While this technique is not new, the adoption of AI has enabled threat actors to improve their campaign templates and construct emails tailored to their recipients.

Additionally, threat actors are incorporating multiple techniques within the same email to improve the overall narrative further.

In this blog, we will discuss a recent campaign observed using third-party email delivery infrastructure to send out over a million financial fraud scam emails that displayed multiple indicators consistent with the use of generative AI during email template creation.

The threat actor impersonated CEOs of multiple target companies, attempting to convince accounts payable departments of the same companies to process an Automated Clearing House (ACH) payment of nearly $50,000. To add legitimacy, the actor included a forwarded email thread (and a fabricated invoice) between the impersonated CEO and ServiceNow (which was also being impersonated).

Read more →