Threat actors sent more than one million AI-assisted invoice fraud emails in a large business email compromise (BEC) campaign targeting enterprise users.
The operation, detected by Microsoft between August 3 and 5, impersonated executives and trusted brands to pressure finance teams into making fraudulent Automated Clearing House (ACH) payments of nearly $50,000.
The campaign primarily targeted organizations in the United States, which received 87.7% of all messages. IT services, business advisory firms, consumer-goods companies, and other enterprises were among the targeted sectors.
Unlike standard invoice scams, the attackers combined several social-engineering techniques in one email.
They impersonated CEOs, CFOs, and presidents of the victim organizations, using executive names in sender display names, Reply-To fields, and email signatures.
The messages included a short approval notice directing accounts payable employees to process an invoice.
To make the request appear legitimate, the attackers added a fabricated ServiceNow annual-subscription invoice and fake forwarded email conversations.
Microsoft stated that ServiceNow and the other organizations named in the campaign were not compromised or involved.
The attackers used fraudulent domains, fake invoices, and impersonated identities to create a believable payment narrative.
AI CEO Invoice Fraud
The fraudulent invoice used ServiceNow branding, logos, itemized charges, invoice dates, payment details, and a bank-transfer instruction.
The “BILLED TO” section was personalized with the targeted organization’s name and executive details, increasing the likelihood that recipients would trust the payment request.

Attackers also embedded a fake email thread between the victim company’s executive and a supposed ServiceNow president.
These messages discussed a software purchase, implementation, and invoice handling. However, defenders could spot several warning signs.
The forwarded messages lacked normal email headers and visual grouping usually found in genuine threads. Some text contained unusual phrases, such as “no need to copy me.”
In other cases, display names did not match the sender addresses, while subject lines used suspicious financial terms including “due bill” and “ACH payment.”
Before the campaign began, the threat actor registered multiple domains. One, service-nowinc[.]com, was registered on July 31 and impersonated ServiceNow.

It appeared in the fake ServiceNow executive’s email address and within the fabricated invoice. Another domain, domainlify[.]net, was used in Reply-To addresses.
Microsoft identified several signs consistent with generative AI-assisted template development.
These included unusually detailed HTML comments, excessive section labels, uniform formatting, capitalized headers, banner-style separators, and repeated use of em dashes.
These clues do not prove that AI created every message, but they suggest attackers may have used AI to build reusable templates and quickly personalize lures for many organizations.
Indicators of Compromise (IOCs)
| Indicator | Type | Description |
|---|---|---|
service-nowinc[.]com | Domain | Lookalike domain impersonating ServiceNow; used in fake executive communications and fraudulent invoice content |
gomez@service-nowinc[.]com | Email address | Impersonated ServiceNow-related email address associated with attacker-controlled bank-payment activity |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Detect 58% more threats with fresh intelligence from 16K+ organizations. Integrate TI Feeds in you SOC
The post Hackers Send 1 Million AI-Assisted CEO Impersonation Emails in Invoice Fraud Campaign appeared first on Cyber Security News.