news.mlab.sh
Back to the feed
threat-intel

Threat Actor Generates 1M Personalized Fraud Emails in 3 Days

High
Summary

A threat actor leveraging AI generated over one million personalized phishing emails targeting organizations, primarily in the US, within three days. The emails mimicked legitimate invoices and created a fabricated email thread to appear as if an executive was requesting the invoice directly from ServiceNow, a cloud services company. This attack demonstrates how AI is rapidly enhancing traditional phishing techniques, making them more convincing and easier to scale, and highlights the need to balance traditional cybersecurity hygiene with AI-powered defenses.

Threat actor leveraging AI generated over one million personalized phishing emails targeting organizations, primarily in the US, within three days. The emails mimicked legitimate invoices and created a fabricated email thread to appear as if an executive was requesting the invoice directly from ServiceNow, a cloud services company. The attacker identified CEOs, CFOs, and presidents at victim organizations and plugged them into the phishing emails' signatures.

This campaign, which ran from Aug. 3 to Aug. 5, demonstrated how AI is rapidly enhancing traditional phishing techniques, making them more convincing and easier to scale. The emails were sent to organizations across industries – IT, consumer goods, and real estate – with 87.7% of the targets located in the US.

Microsoft researchers tracked the campaign, noting that the attacker used AI to quickly gather information about victim organizations – including company websites, executive information, employee roles, press releases, and other public sources – to construct more convincing impersonation emails. They also built multiple AI-driven processes for different parts of the campaign, including information gathering, generating personalized content, and creating templates.

Despite this summer's headspinning, futuristic headlines – of rogue waves of AI agents attacking innocent companies with wanton abandon – experts emphasize that AI's greatest proven threat so far is its ability to buff old-fashioned kinds of cyberattacks. "New AI-native threats like adversarial agents and prompt injection will create new risks, but phishing, impersonation, and fraud already have proven paths to success," Joshua Bartolomie, vice president and global head of threat intelligence at Doppel, tells Dark Reading. "AI makes those attacks faster, cheaper, more personalized, and easier to scale."

Microsoft's recommendations for companies – properly configuring email authentication and spoof protection, implementing email security filters and extended detection and response (XDR) – included little about those cutting-edge, AI-powered cyber defenses common in marketing campaigns today. Khalid recommends that organizations balance investing in straightforward cybersecurity hygiene and frontier tooling. "This campaign is a good example," she says, since standard email filters can pick out malicious artifacts in incoming messages, but AI-powered email protection can analyze those signals at machine speed. "AI isn't a replacement for fundamental security practices," she says. "Ultimately, the best defense is layered: good cyber hygiene and processes, educated employees, and AI-powered security technologies capable of detecting and responding at the same speed attackers are increasingly operating."

Read the full article at Dark Reading