1. Executive summary
Between 3–5 August 2026, Microsoft Threat Intelligence observed a business email compromise (BEC) campaign distributing more than one million fraudulent invoice emails via third-party email delivery infrastructure, impersonating CEOs, CFOs and Presidents of targeted companies to pressure accounts payable staff into processing ACH transfers of nearly $50,000. The campaign layered executive impersonation, ServiceNow vendor branding, a fabricated “ServiceNow Platform — Annual Subscription” invoice, and a forged forwarded email thread into a single narrative — a departure from single-lure invoice scams — and displayed multiple indicators consistent with generative AI use in template construction, though Microsoft cannot independently establish the extent of AI generation. 87.7% of recipients were in the United States, with the remainder distributed elsewhere, including EMEA. No CVE is in scope, no CISA-KEV exploitation state applies, and no named threat actor is identified — attribution is unconfirmed. The bottom-line risk for EMEA financial services is direct financial loss via payment-fraud controls being defeated by socially engineered “internal” approvals, not technical compromise: Microsoft found no evidence that ServiceNow or any referenced legitimate organisation was breached.
2. Regulatory framing
| Article | Trigger (the fact in this item) | Practical impact |
|---|---|---|
| DORA Art. 18: classification of ICT-related incidents and cyber threats | A large-scale, ongoing financial-fraud campaign (1M+ emails, August 2026) explicitly targeting accounts payable functions of enterprises constitutes a cyber threat that financial entities must classify under their incident/cyber-threat taxonomy, distinct from a technical incident. | Ensure payment-fraud attempts and BEC lures reaching finance staff are captured in threat classification and feed the Art. 18 process, not ad-hoc spam handling. |
| DORA Art. 17: ICT-related incident management process | Successful processing of a fraudulent ACH transfer (~$50,000 per attempt) is a financial-loss event whose detection, escalation and recovery (bank recall, law-enforcement referral) must run through the entity's defined ICT-related incident management process. | Pre-define the fraud-escalation path from AP staff to incident management, including out-of-band verification and payment-recall triggers. |
No NIS2 or UK NIS article is directly engaged by this item: the campaign is a fraud/social-engineering threat rather than a disruption of network and information systems, and no reportable incident under NIS2 Art. 23 or UK NIS 2018 OES/RDSP duties is described in the source material.
3. Technical analysis & attack chain
This is a social-engineering fraud campaign, not a malware or exploitation campaign. No vulnerability, payload, persistence mechanism, C2 infrastructure, or data exfiltration is described in the source material. The attack chain below is confirmed from the Microsoft Threat Intelligence blog and The Record's coverage.
Confirmed attack chain
- Domain registration. Threat actors registered impersonation/lookalike domains mimicking the targeted organisations and the impersonated vendor (ServiceNow) before campaign launch.
- Infrastructure. The actor used multiple third-party email service provider accounts to dispatch the mail — trusted delivery infrastructure that lends sender reputation to the wave. Over one million emails were sent between 3 and 5 August 2026.
- Executive impersonation. Emails impersonated executive team members — CEO, CFO, President — of the recipient's own company. The impersonated executive appeared in multiple places: the sender display name, the reply-to display name, and the email signature (name and email address of the spoofed CEO).
- Lure body. The email body contained a simple, direct “approval” of the “invoice below” and urged recipients to request a PDF version if needed — a low-pressure phrasing designed to read as routine internal correspondence.
- Fabricated forwarded thread. Directly below the CEO signature, the actor inserted “forwarded” content: a professional-looking but fabricated email thread between the impersonated CEO and ServiceNow (itself impersonated via the lookalike domains), plus a fabricated “ServiceNow Platform — Annual Subscription” invoice carrying ServiceNow branding and logos, invoice number, issue/due dates, currency, amount due, payment method, and itemised line items. The “BILLED TO” section was personalised to the recipient.
- Payment instruction. The invoice's payment method instructed a bank transfer to accounts controlled by the threat actor. Microsoft observed multiple financial institutions across samples, indicating payment destinations vary between targets.
- Objective. Convince finance personnel to initiate an ACH transfer of nearly $50,000 to actor-controlled accounts.
AI-assistance indicators. Microsoft identified several indicators consistent with generative AI use in template construction: extensive HTML comments, structured section labelling, and highly uniform template construction across the campaign. Caveat: Microsoft states it cannot “independently establish the extent to which AI generated campaign content” — treat AI involvement as assessed-likely, not proven. This assessment is single-sourced (Microsoft Threat Intelligence); no second vendor has corroborated the AI-template indicators.
Targeting. 87.7% of recipients were in the United States; the residual ~12% indicates non-US recipients including potential EMEA targets, but the sources give no EMEA-specific victimology.
Explicitly not present: No malware, no credential harvesting, no links to attacker-controlled phishing kits, and no compromise of any legitimate organisation. Microsoft found no evidence that ServiceNow or any other referenced legitimate organisation was compromised or involved. The related M365 account-takeover campaigns in the wider reporting context (voice-phishing to personal phones, AitM phishing, ARToken panel) are distinct activity and should not be conflated with this invoice-fraud wave.
4. Mitigation & containment
P1 — within 24 hours
- Out-of-band payment verification. Enforce a mandatory callback to a known-good number for any ACH/bank-transfer request above threshold (this campaign: ~$50,000) or any new/changed beneficiary account, regardless of apparent internal executive origin. This single control defeats the entire chain above.
- Hunt retroactively. Search mail telemetry for the August 3–5 2026 window for messages matching the pattern: executive display name + ServiceNow branding + “Annual Subscription” invoice + forwarded-thread structure + third-party/bulk sending infrastructure. Any hit in AP/finance inboxes escalates to fraud review — check whether a transfer was initiated.
- Beneficiary-account controls. Flag and hold first-time or changed beneficiary bank details in AP workflows; the actor used multiple financial institutions, so blocklisting single IBANs is insufficient.
P2 — within 72 hours
- Display-name / reply-to mismatch detection. Deploy or tune mail rules that flag messages where the sender or reply-to display name matches an internal executive but the sending domain/address is external or a newly registered lookalike. This campaign placed the impersonated CEO in sender display name, reply-to display name, and signature — all three are detectable.
- Lookalike-domain monitoring. Register-monitor for homoglyph/typosquat variants of your own domain and key vendor domains (ServiceNow in this lure set); the actors registered impersonation domains pre-campaign.
- AP-targeted awareness. Brief accounts payable specifically on the layered-narrative pattern (executive approval + vendor invoice + forwarded thread) and the “request a PDF version” phrasing. Generic phishing training does not cover this.
P3 — within 7 days
- Third-party mail-infrastructure review. The campaign abused legitimate third-party email service providers. Review inbound mail-flow policy for mail originating from bulk ESPs presenting as internal executives; consider external-sender banners and stripping or flagging forwarded-thread content from untrusted senders.
- Fraud-response runbook. Ensure the incident management process (DORA Art. 17) includes a payment-recall/law-enforcement path for completed fraudulent transfers, with defined timing — recall success rates decay within hours.
5. Indicators of compromise
No atomic indicators of compromise available in the source material. Neither Microsoft's blog excerpt nor The Record's article publishes domains, IP addresses, sender addresses, hashes, or bank account details from this campaign.
Behavioural indicators
| Behaviour | Where to observe | Confidence |
|---|---|---|
| Executive display name (CEO/CFO/President) on mail from external/third-party sending infrastructure, with matching reply-to display name and signature | Email gateway / M365 mail telemetry, August 3–5 2026 window | High — multi-source (Microsoft, The Record) |
| Fabricated “ServiceNow Platform — Annual Subscription” invoice embedded below executive signature, with personalised “BILLED TO” section | AP/finance mailboxes; attachment/inline-image inspection | High — multi-source |
| Forged forwarded email thread between impersonated CEO and “ServiceNow” | Email body structure analysis | High — multi-source |
| Extensive HTML comments, structured section labelling, highly uniform template construction across messages | Mail-body HTML analysis | Medium — single-sourced (Microsoft); AI-involvement indicators, not confirmed generation |
| Payment instruction to bank transfer at one of multiple financial institutions, ~$50,000 amount | AP invoice-processing records | High — multi-source |
6. Detection
The sources contain no atomic artefacts (domains, hashes, exact strings from message bodies, sender addresses) usable to author a YARA or Sigma rule. The behavioural indicators in §5 are narrative patterns, not machine-matchable strings. Authoring a rule that greps for “ServiceNow” or campaign reporting phrases would detect legitimate vendor mail and news coverage, not the threat.
Insufficient indicators to author detection rules.
7. Sources
- Microsoft Threat Intelligence — Protecting organizations from AI-assisted executive impersonation and invoice fraud — https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/ — 2026-09-10
- The Record — Microsoft sees some new wrinkles in invoice-scam emails — https://therecord.media/invoice-scam-emails-new-features-microsoft-researchers — 2026-09-11
Contextual (related M365 social-engineering campaigns, distinct from this item): Help Net Security — Attackers call employees' personal phones to break into Microsoft 365 accounts (2026-09-10); SecurityWeek — Weaponized Email AI Assistants Could Help Attackers Hijack Accounts; The Hacker News — Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails (2026-08); Help Net Security — Attackers are using Microsoft's legitimate login system to camouflage phishing attacks (2026-07-30); Help Net Security — The ARToken phishing panel targets Microsoft 365 accounts (2026-07-01).
8. Adverse Trace position
This is a high-volume, high-sophistication social-engineering campaign with a direct financial-loss objective — materially more dangerous to accounts payable functions than commodity phishing, because it defeats human pattern-matching rather than technical controls, but it involves no vulnerability, no malware and no compromise of any legitimate organisation, including ServiceNow. Severity for EMEA financial services is medium: the 87.7% US targeting suggests EMEA exposure is currently secondary, but the techniques (AI-assisted templating, layered impersonation narratives, trusted third-party sending infrastructure) are trivially retargeted and the ~$50,000-per-attempt loss figure is meaningful at AP scale. Attribution is unconfirmed — no actor is named in any source, and the AI-generation assessment is single-sourced to Microsoft and explicitly hedged by them; verify before treating AI involvement as established in client reporting. Adverse Trace will monitor for a second-source technical breakdown of this campaign (domains, sending infrastructure, mule accounts), for EMEA-specific victimology, and for convergence between this fraud wave and the distinct M365 account-takeover activity in the same reporting period.
Published via PulseTrace — Adverse Trace threat intelligence.