Microsoft sees some new wrinkles in invoice-scam emails
Microsoft researchers have identified a sophisticated new wave of business email compromise (BEC) scams leveraging AI to create more convincing and layered fraudulent emails. Attackers are now using AI to generate campaign templates and fabricate email chains, impersonating executives and vendors to trick accounts payable departments into sending large, unauthorized payments. The campaign is primarily targeting American businesses.
Microsoft researchers have recently uncovered a significant increase in business email compromise (BEC) scams, now utilizing artificial intelligence to enhance their effectiveness. These new attacks are far more complex than traditional BEC schemes, which typically relied on a single social engineering lure.
In early August, a campaign consisting of over a million emails was launched, targeting Microsoft users and designed to defraud companies by tricking accounts payable departments into sending payments of nearly $50,000. The attackers are impersonating top executives and leveraging third-party services to distribute the emails.
To bolster their credibility, the emails now include fabricated email chains, mimicking legitimate communications between the fake executive and ServiceNow, a cloud-based enterprise platform. These fabricated email threads presented invoices supposedly received from ServiceNow, further convincing recipients to comply with the fraudulent requests.
Researchers noted several indicators consistent with AI-assisted template development, including extensive HTML comments, structured section labeling, and highly uniform template construction. While Microsoft acknowledges the potential use of generative AI, they cannot definitively determine the extent to which AI generated the campaign content.
“Unlike traditional invoice scams that rely on a single social engineering lure, this campaign layered executive impersonation, vendor branding, fabricated invoices, and supporting email conversations into a unified narrative intended to reduce recipient skepticism,” the report stated.
“Safeguards need to reflect that reality, with greater attention to how models can be used to generate deceptive content at volume,” said Nick Tausek, lead security automation architect at Swimlane. “Policymakers also need to account for how quickly useful AI capabilities can be adapted once they’re in an attacker’s hands.”