2818 stories
·
0 followers

Hackers Send 1 Million AI-Assisted CEO Impersonation Emails in Invoice Fraud Campaign

1 Share

Threat actors sent more than one million AI-assisted invoice fraud emails in a large business email compromise (BEC) campaign targeting enterprise users.

The operation, detected by Microsoft between August 3 and 5, impersonated executives and trusted brands to pressure finance teams into making fraudulent Automated Clearing House (ACH) payments of nearly $50,000.

The campaign primarily targeted organizations in the United States, which received 87.7% of all messages. IT services, business advisory firms, consumer-goods companies, and other enterprises were among the targeted sectors.

Unlike standard invoice scams, the attackers combined several social-engineering techniques in one email.

They impersonated CEOs, CFOs, and presidents of the victim organizations, using executive names in sender display names, Reply-To fields, and email signatures.

The messages included a short approval notice directing accounts payable employees to process an invoice.

To make the request appear legitimate, the attackers added a fabricated ServiceNow annual-subscription invoice and fake forwarded email conversations.

Microsoft stated that ServiceNow and the other organizations named in the campaign were not compromised or involved.

The attackers used fraudulent domains, fake invoices, and impersonated identities to create a believable payment narrative.

AI CEO Invoice Fraud

The fraudulent invoice used ServiceNow branding, logos, itemized charges, invoice dates, payment details, and a bank-transfer instruction.

The “BILLED TO” section was personalized with the targeted organization’s name and executive details, increasing the likelihood that recipients would trust the payment request.

Attack chain showing domain registration, executive impersonation, invoice fraud delivery, ACH payment execution, and financial theft (Source: microsoft)
Attack chain showing domain registration, executive impersonation, invoice fraud delivery, ACH payment execution, and financial theft (Source: microsoft)

Attackers also embedded a fake email thread between the victim company’s executive and a supposed ServiceNow president.

These messages discussed a software purchase, implementation, and invoice handling. However, defenders could spot several warning signs.

The forwarded messages lacked normal email headers and visual grouping usually found in genuine threads. Some text contained unusual phrases, such as “no need to copy me.”

In other cases, display names did not match the sender addresses, while subject lines used suspicious financial terms including “due bill” and “ACH payment.”

Before the campaign began, the threat actor registered multiple domains. One, service-nowinc[.]com, was registered on July 31 and impersonated ServiceNow.

Industry distribution of targeted enterprises of this campaign with ‘IT services & business advisory’ along with ‘Consumer goods’ and others (Source: microsoft)
Industry distribution of targeted enterprises of this campaign with ‘IT services & business advisory’ along with ‘Consumer goods’ and others (Source: microsoft)

It appeared in the fake ServiceNow executive’s email address and within the fabricated invoice. Another domain, domainlify[.]net, was used in Reply-To addresses.

Microsoft identified several signs consistent with generative AI-assisted template development.

These included unusually detailed HTML comments, excessive section labels, uniform formatting, capitalized headers, banner-style separators, and repeated use of em dashes.

These clues do not prove that AI created every message, but they suggest attackers may have used AI to build reusable templates and quickly personalize lures for many organizations.

Indicators of Compromise (IOCs)

IndicatorTypeDescription
service-nowinc[.]comDomainLookalike domain impersonating ServiceNow; used in fake executive communications and fraudulent invoice content
gomez@service-nowinc[.]comEmail addressImpersonated ServiceNow-related email address associated with attacker-controlled bank-payment activity

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Detect 58% more threats with fresh intelligence from 16K+ organizations. Integrate TI Feeds in you SOC

The post Hackers Send 1 Million AI-Assisted CEO Impersonation Emails in Invoice Fraud Campaign appeared first on Cyber Security News.



Read the whole story
NerdsToGo
9 hours ago
reply
Share this story
Delete

Trezor: 347,000 users targeted in phishing attacks after Brevo breach

1 Share
Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link. [...]
Read the whole story
NerdsToGo
9 hours ago
reply
Share this story
Delete

IDScan confirms breach after 153 million driver’s licenses leak on dark web

1 Share

Days after reports linked IDScan to a dark web database holding more than 153 million driver’s license scans, the identity verification company has confirmed hackers accessed customer data stored on its cloud platform. The Louisiana-based firm, which processes ID checks for car rental companies, retailers and cannabis dispensaries, posted a notice on its website September 4 acknowledging the incident. “On or around September 1, 2026, IDScan.net received information indicating that certain data may have been … More

The post IDScan confirms breach after 153 million driver’s licenses leak on dark web appeared first on Help Net Security.

Read the whole story
NerdsToGo
9 hours ago
reply
Share this story
Delete

GitLab Vulnerability Exploited One Day After Disclosure

1 Share

The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server.

The post GitLab Vulnerability Exploited One Day After Disclosure appeared first on SecurityWeek.

Read the whole story
NerdsToGo
9 hours ago
reply
Share this story
Delete

Florida confirms DMV database breached via stolen police account

1 Share
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee. [...]
Read the whole story
NerdsToGo
9 hours ago
reply
Share this story
Delete

Hackers abused Claude to extract secrets from 1.8M Android apps

1 Share
Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes. [...]
Read the whole story
NerdsToGo
9 hours ago
reply
Share this story
Delete
Next Page of Stories