Microsoft reports a real, large-scale email campaign that impersonated company executives and ServiceNow to pressure accounts payable teams into sending nearly $50,000 via ACH/bank transfer. The emails bundled a CEO “approval,” a fake ServiceNow-branded invoice, and a fabricated forwarded thread to make the request look routine and trustworthy.
Key findings
- Microsoft observed “more than a million emails” sent over a short window (Aug 3–5), primarily targeting U.S. users.
- Attackers impersonated internal executives (CEO/CFO/President) to pressure Accounts Payable to send an ACH payment “of nearly $50,000.”
- The lure combined multiple credibility layers: executive impersonation in display name/reply-to/signature, a fabricated ServiceNow invoice, and a fake forwarded email conversation.
- Attackers used lookalike domains, including a ServiceNow-themed domain registered shortly before the campaign.
- Microsoft noted indicators consistent with generative-AI-assisted email template creation (highly uniform structure and verbose HTML comments).
Who’s being targeted
- Commonly targeted roles: Accounts Payable, Finance, Procurement, Executive assistants.
- Affected industries: IT services & business advisory, Consumer goods, Enterprise (multi-industry) organizations.
- Attack channels: email.
- Impersonated: Target company CEO (executive team member), ServiceNow (and its President) plus the target company executive.
Awareness takeaways
- Treat executive ‘approve and pay’ emails as high-risk and verify payment requests out-of-band using a known contact method.
- Don’t trust embedded ‘forwarded’ threads or branded invoices at face value; validate the vendor, domain, and invoice workflow through normal procurement controls.
- Train staff to spot technical and formatting inconsistencies common in fake forwarded threads (missing headers, odd phrasing, misaligned threading).
- Be cautious of lookalike domains and unexpected reply-to addresses in payment conversations; confirm the sender domain is correct before acting.
Red flags to watch for
- Display name and reply-to/signature identity cues don’t match the real sender (“sender display name, reply-to display name, and in the email signature” were spoofed)
- Pressure to pay based on a brief approval rather than normal procurement controls
- Unusual finance-themed subject keywords (e.g., “due bill”, “ACH Parment”)
- “Forwarded” thread lacks normal forwarded headers/metadata
- Lookalike domain used for the vendor identity (ServiceNow-themed domain)
- Invoice instructs payment to bank accounts that may vary by target (changing destinations is suspicious)
Read the video transcript
Imagine this: an email from your CEO, approving a ServiceNow invoice and asking you to push a $50,000 ACH today. This is a real AI-assisted CEO invoice scam. More than a million of these went out. The email spoofs your CEO in the display name, reply-to, and signature, then tacks on a fake “ServiceNow Platform, Annual Subscription” invoice and a fabricated forwarded thread to make it feel routine. Here’s the tell: the CEO name is everywhere, but the domain isn’t right. The “ServiceNow” invoice actually comes from a lookalike like service-nowinc.com, the forwarded thread has no real headers, and the invoice tells you to wire money to a bank account that doesn’t match your usual vendor details. If you ever get a short ‘approved, please pay via ACH’ email from an executive, stop. Don’t reply, don’t wire. Use a known phone number or chat to confirm the request out-of-band before you move a dollar.