Protecting organizations from AI-assisted executive impersonation and invoice fraud
September 10, 2026 · Microsoft Security · Severity: MEDIUM
Microsoft Security discusses the growing threat of AI-assisted executive impersonation and invoice fraud attacks. These attacks use generative AI to create highly convincing phishing emails and fake communications from company leaders. The article provides mitigation guidance, including payment verification protocols and AI-enhanced email filtering to protect against these sophisticated scams.
Threat actors are increasingly improving their tactics to make suspicious emails look like legitimate email notifications to potential victims, deploying techniques that impersonate internally sent emails from executive team members. While this technique is not new, the adoption of AI has enabled threat actors to improve their campaign templates and construct emails tailored to their recipients. Additionally, threat actors are incorporating multiple techniques within the same email to improve the overall narrative further.
In this blog, we will discuss a recent campaign observed using third-party email delivery infrastructure to send out over a million financial fraud scam emails that displayed multiple indicators consistent with the use of generative AI during email template creation. The threat actor impersonated CEOs of multiple target companies, attempting to convince accounts payable departments of the same companies to process an Automated Clearing House (ACH) payment of nearly $50,000. To add legitimacy, the actor included a forwarded email thread (and a fabricated invoice) between the impersonated CEO and ServiceNow (which was also being impersonated).
Attack chain overview
The campaign follows steps before and during the execution of the campaign: threat actors register impersonation domains, send executive-themed payment requests through trusted infrastructure, embed fabricated invoices and supporting conversations, and attempt to convince finance personnel to initiate ACH transfers.

Email Delivery
Between August 3 and 5, Microsoft detected a campaign consisting of more than a million emails targeting enterprise users. The attacker used multiple third-party email service accounts to send out the emails. A huge majority of these emails were sent to users in the United States (87.7% of the total campaign).


Unlike traditional invoice scams that rely on a single social engineering lure, this campaign layered executive impersonation, vendor branding, fabricated invoices, and supporting email conversations into a unified narrative intended to reduce recipient skepticism.
The threat actor impersonated executive team members (such as a CEO, CFO, President) of multiple targeted companies, attempting to convince accounts payable departments of the same companies to process an ACH payment of nearly $50,000. More specifically, the CEOs were impersonated in multiple places in the email such as in the sender display name, reply-to display name, and in the email signature. Email bodies contained a simple and direct “approval” of the “invoice below” as well as urged users to request a PDF version if they need it. Additionally, as mentioned earlier, the email signature contained certain details about the spoofed CEO such as name and email address.

Important note: Throughout this campaign, threat actors impersonated legitimate organizations using attacker-controlled infrastructure, fabricated communications, and lookalike domains. Microsoft found no evidence that the legitimate organizations referenced in the lures, including ServiceNow, were compromised or involved in the activity. Rather, the campaign relied on fraudulent domains and content designed to mimic trusted brands and individuals.
The threat actor did not stop there. To add further legitimacy, directly below the CEO signature, the actor included “forwarded” content , specifically a professional looking but fabricated “ServiceNow Platform — Annual Subscription” invoice. The extremely detailed invoice contains various ServiceNow branding and logos. It has basic invoice details such as invoice number, issue and due dates, currency, amount due, payment method, and itemized line items. The payment method instructed is a bank transfer to accounts controlled by the threat actor. Microsoft observed the use of multiple financial institutions across samples, indicating that payment destinations may vary between targets. Certain parts of the invoice are personalized to the recipient. Specifically, the “BILLED TO” section has the recipient company name and executive name.
The invoice shown below is a threat actor-created impersonation and was not issued by ServiceNow.

Key Takeaways
- AI-assisted executive impersonation and invoice fraud are emerging threats that exploit generative AI to create convincing fake communications from company leaders. Attackers use deepfakes and realistic text to trick employees into authorizing fraudulent payments or sharing sensitive data. Organizations must implement multifactor authentication and verification protocols for financial transactions to combat these sophisticated scams.
- Microsoft's article outlines an attack chain involving email delivery, domain registration, and generative AI usage to impersonate executives. The attackers register look-alike domains and craft emails that mimic the tone and style of real executives. This technique increases the likelihood of success compared to traditional phishing methods due to the personalization enabled by AI.
- Mitigation guidance includes deploying AI-powered email filters, training employees to verify unusual financial requests through alternative channels, and adopting zero-trust principles for payment approvals. Companies should also monitor for unauthorized domain registrations and implement strict invoice validation processes. These measures can significantly reduce the risk of falling victim to AI-enhanced fraud campaigns.