The attackers built what looked like legitimate business transactions complete with invoices, executive approvals, and email threads.
Key Takeaways:
Business email compromise (BEC) attacks have long relied on social engineering, but attackers are now using generative AI to make fraudulent payment requests far more convincing. As organizations increasingly automate workflows and trust digital communications, finance departments face more pressure to distinguish legitimate business requests from increasingly sophisticated scams.
According to the Microsoft Security Research & Threat Intelligence team, attackers launched a campaign that delivered more than one million emails between August 3 and 5, which primarily targeted U.S.-based organizations. The attackers combined several deception techniques into a single narrative. They impersonated company executives such as CEOs and CFOs, inserted fabricated invoices, and included fake email conversations designed to make payment requests appear authentic.
This campaign specifically targeted accounts payable personnel, which urged them to approve and process Automated Clearing House (ACH) transfers of nearly $50,000. To strengthen credibility, the threat actors personalized invoices with company names and executive details while imitating trusted brands. However, Microsoft didn’t find any evidence that the legitimate organizations referenced in the emails had been compromised.
Microsoft observed several indicators suggesting that generative AI may have played a role in creating campaign templates. The emails contained highly structured formatting, extensive HTML comments, consistent template designs, and other characteristics commonly associated with AI-generated content. The evidence does not prove how much content was created by AI, but it suggests attackers are leveraging these tools to scale and refine social engineering campaigns.
The result is a more professional and persuasive fraud attempt that can be harder for employees to identify. The attackers created a fabricated business transaction complete with invoices, executive approvals, and supporting correspondence.
Microsoft found several indicators that security teams can use to identify these scams. The fabricated email threads lacked the technical headers normally found in forwarded messages, contained unusual language, and included inconsistencies in the conversation narrative. Attackers also registered lookalike domains shortly before the campaign began, including domains designed to mimic trusted organizations.
These flaws demonstrate that AI-assisted attacks may improve realism, but they do not eliminate operational mistakes that security teams can use for detection and investigation.
Microsoft recommends a layered defense strategy that combines email authentication controls, anti-phishing technologies, and post-delivery remediation capabilities. The company highlights technologies such as SPF, DKIM, DMARC, Zero-hour Auto Purge (ZAP), automatic attack disruption, and Microsoft Defender protections as ways to reduce the likelihood that fraudulent payment requests reach finance personnel.
Organizations are also encouraged to strengthen payment verification procedures and train employees to scrutinize requests involving invoices, wire transfers, or ACH transactions, especially when they appear to come from senior executives.
This campaign demonstrates that the same AI technologies that help improve productivity and security operations can also help attackers create more convincing fraud schemes. The security platforms are becoming better at detecting suspicious activity, but organizations may need to invest more heavily in technical controls, employee awareness programs, and payment verification processes to keep pace with increasingly sophisticated threats.
As AI lowers the barrier to producing realistic phishing content at scale, the advantage may shift toward organizations that combine advanced detection capabilities with strong financial controls and human verification processes.