Microsoft traced more than 1 million executive-impersonation emails. The payment control still failed off-screen.
The campaign used lookalike domains, fabricated invoice threads and uniform AI-assisted templates to request an ACH payment of almost $50,000. Content detection helps, but independent payment verification breaks the fraud path.
By Parminder Kumar Sharma · · 3 min read

The campaign industrialised a familiar request
Microsoft says a campaign sent more than one million emails between 3 and 5 August, with 87.7% directed at recipients in the United States. Messages impersonated senior leaders and service brands, used lookalike domains and asked for urgent invoice handling. One example sought an ACH payment of almost $50,000.
The lure included a fabricated invoice and a fake forwarded thread to create history and authority. Microsoft says there is no evidence that the legitimate organisations named in the messages, including ServiceNow, were compromised. The delivery relied on attacker-controlled and third-party infrastructure rather than a breach of those brands.
Authority, continuity and urgency made the message persuasive
The operation combined several trust signals. An executive name supplied authority. A copied brand and lookalike domain supplied familiarity. A fake forwarded exchange supplied continuity. The payment request supplied urgency and a measurable attacker objective.
Email authentication can block some spoofing, but it cannot establish that an executive approved a bank-detail change or urgent transfer. The financial decision needs independent evidence.
The fraud path and its strongest interruption
| Step | Attacker signal | Control |
|---|---|---|
| Impersonate | Executive display name and branded formatting | External-sender labels and lookalike-domain detection |
| Create history | Fabricated forwarded thread and invoice | Inspect original headers and business records |
| Apply pressure | Urgent or confidential instruction | No bypass of payment procedure |
| Move money | New ACH destination | Call-back to a trusted, pre-recorded contact |
Move the final approval outside the email thread
Require two-person approval for new beneficiaries and material payments. Verify changes using a telephone number or workflow already held in the supplier or executive record, not contact details in the new message. Pause when a request combines urgency, secrecy and a payment change.
Detection teams should correlate newly registered lookalike domains, unusual external sender patterns, repeated invoice templates and bursts of near-identical mail. Finance teams should record the independent verification method so an auditor can see why the payment proceeded.
The position
AI can make impersonation campaigns cheaper to personalise and easier to scale. It does not remove the attacker’s dependency on a business process that accepts an email as payment authority.
Organisations should improve mail detection, but the highest-confidence defence remains a financial control: separate the instruction from the verification and require evidence from a trusted channel.
Sources
- PrimaryProtecting organizations from AI-assisted executive impersonation and invoice fraudMicrosoft Securityaccessed 2026-09-13


