AI-Assisted CEO Invoice Scam Pushes $50K ACH

Microsoft Security Blog · High sophistication
Last updated September 10, 2026

Microsoft reports a real, large-scale email campaign that impersonated company executives and ServiceNow to pressure accounts payable teams into sending nearly $50,000 via ACH/bank transfer. The emails bundled a CEO “approval,” a fake ServiceNow-branded invoice, and a fabricated forwarded thread to make the request look routine and trustworthy.

Key findings

  • Microsoft observed “more than a million emails” sent over a short window (Aug 3–5), primarily targeting U.S. users.
  • Attackers impersonated internal executives (CEO/CFO/President) to pressure Accounts Payable to send an ACH payment “of nearly $50,000.”
  • The lure combined multiple credibility layers: executive impersonation in display name/reply-to/signature, a fabricated ServiceNow invoice, and a fake forwarded email conversation.
  • Attackers used lookalike domains, including a ServiceNow-themed domain registered shortly before the campaign.
  • Microsoft noted indicators consistent with generative-AI-assisted email template creation (highly uniform structure and verbose HTML comments).

Who’s being targeted

  • Commonly targeted roles: Accounts Payable, Finance, Procurement, Executive assistants.
  • Affected industries: IT services & business advisory, Consumer goods, Enterprise (multi-industry) organizations.
  • Attack channels: email.
  • Impersonated: Target company CEO (executive team member), ServiceNow (and its President) plus the target company executive.

Awareness takeaways

  • Treat executive ‘approve and pay’ emails as high-risk and verify payment requests out-of-band using a known contact method.
  • Don’t trust embedded ‘forwarded’ threads or branded invoices at face value; validate the vendor, domain, and invoice workflow through normal procurement controls.
  • Train staff to spot technical and formatting inconsistencies common in fake forwarded threads (missing headers, odd phrasing, misaligned threading).
  • Be cautious of lookalike domains and unexpected reply-to addresses in payment conversations; confirm the sender domain is correct before acting.

Red flags to watch for

  • Display name and reply-to/signature identity cues don’t match the real sender (“sender display name, reply-to display name, and in the email signature” were spoofed)
  • Pressure to pay based on a brief approval rather than normal procurement controls
  • Unusual finance-themed subject keywords (e.g., “due bill”, “ACH Parment”)
  • “Forwarded” thread lacks normal forwarded headers/metadata
  • Lookalike domain used for the vendor identity (ServiceNow-themed domain)
  • Invoice instructs payment to bank accounts that may vary by target (changing destinations is suspicious)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine this: an email from your CEO, approving a ServiceNow invoice and asking you to push a $50,000 ACH today. This is a real AI-assisted CEO invoice scam. More than a million of these went out. The email spoofs your CEO in the display name, reply-to, and signature, then tacks on a fake “ServiceNow Platform, Annual Subscription” invoice and a fabricated forwarded thread to make it feel routine. Here’s the tell: the CEO name is everywhere, but the domain isn’t right. The “ServiceNow” invoice actually comes from a lookalike like service-nowinc.com, the forwarded thread has no real headers, and the invoice tells you to wire money to a bank account that doesn’t match your usual vendor details. If you ever get a short ‘approved, please pay via ACH’ email from an executive, stop. Don’t reply, don’t wire. Use a known phone number or chat to confirm the request out-of-band before you move a dollar.

Similar attacks

BigBear 2.0 PhaaS Steals 5,100+ M365 Logins

BigBear 2.0 PhaaS Steals 5,100+ M365 Logins

Researchers say the “BigBear 2.0” phishing-as-a-service operation stole over 5,100 Microsoft 365 credential records across 461 organizations by capturing passwords and session cookies. The campaign used an adversary-in-the-middle setup to bypass MFA and maintain access, with stolen data sent to…

September 8, 2026
Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026
Deepfake CFO Scam Turns Phishing Into Video Wire Fraud

Deepfake CFO Scam Turns Phishing Into Video Wire Fraud

The article describes how modern phishing can start with an email impersonation and then move into live deepfake video calls to pressure employees into sending money. It cites a widely reported case at engineering firm Arup where an employee, convinced by a deepfake video call featuring synthetic…

August 19, 2026
Voicemail Phish Steals Microsoft 365 Sessions

Voicemail Phish Steals Microsoft 365 Sessions

Researchers describe an active, widespread email campaign that tricks employees with voicemail-themed messages and steals Microsoft 365 login sessions (including MFA codes). After taking over accounts, attackers quietly search and collect payroll/HR/finance emails and identify people involved in…

August 7, 2026
Criminals Use AI Pretexts to Bypass Guardrails

Criminals Use AI Pretexts to Bypass Guardrails

Research from Cisco Talos and CrowdStrike says criminals are building AI into everyday operations, from writing malicious code to scaling fraud infrastructure. The reports describe real prompt logs where attackers use simple “authorized testing” claims to trick AI tools into helping them, plus…

August 6, 2026
“No-Action” Emails Trigger OWA Mailbox Takeover

“No-Action” Emails Trigger OWA Mailbox Takeover

Russian-linked threat actors sent generic-looking informational emails that required no clicking, but simply opening them in vulnerable Outlook Web Access (OWA) could trigger a hidden exploit. The campaign targeted government and multiple industries, then installed a stealthy browser-based implant…

July 30, 2026