Researchers at Microsoft are tracking an AI-assisted phishing campaign that sent over a million emails attempting to conduct payment diversion scams.
“The threat actor impersonated executive team members (such as a CEO, CFO, President) of multiple targeted companies, attempting to convince accounts payable departments of the same companies to process an [Automated Clearing House] payment of nearly $50,000,” Microsoft says. “More specifically, the CEOs were impersonated in multiple places in the email such as in the sender display name, reply-to display name, and in the email signature. Email bodies contained a simple and direct ‘approval’ of the ‘invoice below’ as well as urged users to request a PDF version if they need it. Additionally, the email signature contained certain details about the spoofed CEO such as name and email address.”
Additionally, the phishing emails included legitimate-looking invoices that were customized for the targeted organizations. These templates were likely crafted using generative AI, allowing the threat actors to scale the campaign with very little effort.
“To add further legitimacy, directly below the CEO signature, the actor included ‘forwarded’ content, specifically a professional-looking but fabricated ‘ServiceNow Platform — Annual Subscription’ invoice,” the researchers write. “The extremely detailed invoice contains various ServiceNow branding and logos. It has basic invoice details such as invoice number, issue and due dates, currency, amount due, payment method, and itemized line items. The payment method instructed is a bank transfer to accounts controlled by the threat actor. Microsoft observed the use of multiple financial institutions across samples, indicating that payment destinations may vary between targets. Certain parts of the invoice are personalized to the recipient. Specifically, the ‘BILLED TO’ section has the recipient company name and executive name.”
While these social engineering tactics aren’t new, Microsoft says the phishing campaign stands out due to how it “layered executive impersonation, vendor branding, fabricated invoices, and supporting email conversations into a unified narrative intended to reduce recipient skepticism.”
Microsoft has the story: https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/
