A large email fraud campaign used fake CEO messages and invoices to push employees toward payments of nearly $50,000. The operation did not rely on a malicious attachment or software flaw. Instead, it used ordinary email to deliver a scam.
The attackers sent over one million messages to users between August 3 and 5. Most recipients were in the United States, representing 87.7% of the campaign.
Their objective was to persuade accounts-payable staff to approve an Automated Clearing House, or ACH, transfer to criminal-controlled bank accounts.
Microsoft said in a report shared with Cyber Security News (CSN) that analysts identified signs consistent with AI-assisted template development.
It was a business email compromise campaign using impersonation, fake supplier material, and personalised messages, not malware. The scale matters because the messages resembled routine internal approvals, where speed can be valued over scrutiny.
Finance teams received a believable request backed by an executive and vendor. Microsoft found no evidence that organisations named in the lures, including ServiceNow, were compromised or involved.
Hackers Impersonate CEOs in 1 Million Emails
The emails copied the identities of senior leaders, including CEOs, CFOs, and presidents, at targeted companies. A spoofed CEO appeared in the sender display name, reply-to display name, and signature. The short message approved an invoice and told recipients to request a PDF if needed.
.webp)
That familiar tone can make this fraud difficult to spot. Unlike a basic invoice scam, the actor built a complete story around the payment request. As business email compromise attacks grow, criminals use trusted roles and everyday financial processes to lower a recipient’s guard.
Below the executive signature, victims saw a forwarded annual-subscription invoice carrying ServiceNow branding. It included invoice numbers, dates, currency, an amount due, payment details, and itemised charges.
The billed-to area was tailored with the recipient company’s name and an executive’s name, adding a personal touch to the deception. The invoice instructed staff to make a bank transfer, while destination accounts belonged to the attacker.
Microsoft observed multiple financial institutions across samples, suggesting payment routes could differ by target. The criminals inserted a supposed executive exchange to make the purchase appear approved.
Several warning signs remained. The fake forwarded messages lacked normal headers, and they were left aligned rather than visually grouped.
.webp)
Display names did not always match sender addresses, while subjects used odd phrases, such as “due bill” and “ACH Parment.” These details remain valuable checks alongside recent phishing threat reporting.
AI Templates Amplify Invoice Fraud
Before sending the messages, the actor registered lookalike domains and used third-party delivery accounts to distribute the campaign.
One ServiceNow-style domain appeared in the fake president’s address and invoice contact details; another was used in the Reply-To field. This made a fraudulent request look like vendor correspondence.
Researchers also saw extensive HTML comments, highly structured sections, and consistent template construction, all signs compatible with generative-AI assistance.
These observations do not prove how much content AI created. They do show how automated drafting can help criminals produce target-specific material, a concern raised by AI phishing defense guidance.
.webp)
Organisations should make payment verification a process, not a judgment call. Requests to change bank details, approve invoices, or send urgent transfers should be checked through a known phone number or another independent channel.
Staff should never rely only on a reply to the email that made the request. Defenders should also configure email authentication, including SPF, DKIM, and DMARC, and apply spoof protection and filtering.
Teams can review mail-flow settings, enable post-delivery removal or quarantine where available, and train finance personnel to inspect addresses and message history.
Coverage of finance mailbox takeover fraud shows why a layered approach matters when a convincing email can trigger a costly payment. Finally, organisations should give finance employees a route to report suspected fraud.
A short verification pause can stop a transfer before money leaves the business. Monitoring the domains and sender addresses below can help find related messages and block future attempts.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Domain | service-nowinc[.]com |
Domain impersonating ServiceNow |
| Email address | gomez@service-nowinc[.]com |
Email address associated with a bank account |
| Email address | notifications@uinsure[.]co[.]uk |
Sender email address used to send campaign emails |
| Email address | info@tivityhealth[.]com |
Sender email address used to send campaign emails |
| Email address | no-reply@lumalisboa[.]com |
Sender email address used to send campaign emails |
| Email address | noreply@mctci[.]com |
Sender email address used to send campaign emails |
| Email address | info@nuf[.]co[.]jp |
Sender email address used to send campaign emails |
| Email address | info@lohnsteuerhilfe-aktuell-verein[.]de |
Sender email address used to send campaign emails |
| Email address | info@tovimbatista[.]pt |
Sender email address used to send campaign emails |
| Email address | contact@eemusicclass[.]co[.]uk |
Sender email address used to send campaign emails |
| Email address | info@lifeones[.]com |
Sender email address used to send campaign emails |
| Domain | domainlify[.]net |
Newly registered domain used in the Reply-To address |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.
The post Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments appeared first on Cyber Security News.
