~/f4n6 $ grep -r "Protecting organizations from AI-assisted executive impersonation and invoice fraud" ./investigations/ --include="*.md"

Protecting organizations from AI-assisted executive impersonation and invoice fraud

Jeff Davies 10 Sep 2026 9 min read


1. Executive summary

Microsoft Threat Intelligence reports a large-scale business email compromise (BEC) / invoice-fraud campaign that delivered over one million emails between 3–5 August 2026 via third-party email delivery infrastructure, 87.7% of which targeted users in the United States. The actor impersonated CEOs, CFOs and Presidents of target companies to pressure their own accounts payable departments into processing an ACH payment of nearly $50,000, layering a fabricated "ServiceNow Platform — Annual Subscription" invoice and a spoofed executive-to-executive email thread into a single narrative. The email templates show multiple indicators consistent with generative AI assistance in their construction. No CVE, malware payload or compromise of the impersonated brands (including ServiceNow) is involved — this is pure social engineering against payment processes, and the loss event is a fraudulent funds transfer, not a data breach. EMEA financial services clients should treat this as a direct test of payment-verification and callback controls in accounts payable, not as a technical patching problem. Attribution is not named by Microsoft; no MITRE ATT&CK group profile is available in our verified reference data, so attribution is unconfirmed.

2. Regulatory framing

Article Trigger (the fact in this item) Practical impact
DORA Art. 18: classification of ICT-related incidents and cyber threats A campaign of 1M+ targeted fraud emails impersonating client executives and a named vendor (ServiceNow), with lookalike domains still live, constitutes a cyber threat that clients must classify under their ICT incident and cyber-threat taxonomy even where no payment has yet been made. Classify any receipt of these lures as a cyber threat; classify any completed/attempted fraudulent transfer as an ICT-related incident and feed the classification into the Art. 19 major-incident assessment.
DORA Art. 19: reporting of major ICT-related incidents to competent authorities Where a fraudulent ACH transfer of ~$50,000 is actually executed (or an attempted transfer is disrupted late), the financial loss and the compromise of the payment process may meet client-specific major-incident thresholds. If a transfer is executed, run the Art. 19 materiality assessment on the fraud loss and process failure; do not assume BEC is out of scope of ICT-related incident reporting.

No NIS2 or UK NIS article is engaged here on the facts provided: the campaign is a fraud attempt against payment processes, not a disruption of network and information systems, and no incident affecting an NIS2/UK NIS-regulated entity's systems is described in the source.

3. Technical analysis & attack chain

Confirmed attack chain (all steps from the Microsoft report)

  1. Pre-campaign reconnaissance (T1591, T1598). The actor gathered publicly available information on target organisations — executives, finance personnel, vendors and business relationships — to build the invoice-fraud narrative.
  2. Infrastructure acquisition (T1583.001, T1585.002, T1583). On 31 July 2026 the actor registered two domains: service-nowinc[.]com (a ServiceNow lookalike, used for the spoofed "ServiceNow President" email address and as the contact email printed on the fake invoice) and domainlify[.]net (used in the Reply-To address). The actor also established accounts on multiple third-party email services to send the campaign.
  3. Delivery (T1566, T1566.003). Between 3–5 August 2026, over one million emails were sent to enterprise users through those third-party email service accounts. 87.7% of recipients were in the United States.
  4. Impersonation layer (T1656, T1036). Each email impersonated an executive of the recipient's own company (CEO, CFO or President) in three places: the sender display name, the Reply-To display name, and the email signature (which carried the spoofed executive's name and email address). The body was a short, direct "approval" of "the invoice below", urging the recipient to request a PDF version if needed.
  5. Fabricated documentation (T1566.001). Below the executive signature, the email embedded a "forwarded" fake invoice titled "ServiceNow Platform — Annual Subscription", complete with ServiceNow branding and logos, invoice number, issue/due dates, currency, amount due, payment method and itemised line items. The "BILLED TO" section was personalised with the recipient company name and executive name. Payment method was a bank transfer to actor-controlled accounts; Microsoft observed multiple financial institutions across samples, so the destination account varies by target.
  6. Supporting thread forgery. Below the invoice, two further "forwarded" emails depicted a short conversation between the impersonated company executive and the impersonated ServiceNow President discussing the purchase, implementation and invoice handling.
  7. Intended impact (T1657). Convince accounts payable staff to initiate an ACH transfer of nearly $50,000 to the actor-controlled account.

AI-assistance indicators. Microsoft attributes the template construction as "consistent with the use of generative AI" based on: extensive HTML comments, structured section labelling, highly uniform template construction, use of the em dash ("—") and banner lines ("=========="), and the observation that invoice identifiers and narrative structure stayed largely constant across samples while organisation-specific details changed per target. Microsoft explicitly caveats that these indicators "do not independently establish the extent to which AI generated campaign content." Treat the AI-assistance claim as an assessed likelihood, not a proven fact.

What is NOT present. No malware, no credential-harvesting pages, no exploited CVE, no payload. Microsoft found no evidence that ServiceNow or any other referenced legitimate organisation was compromised or involved. The fraud completes entirely in the human/payment layer.

Confidence caveat. All technical detail in this section is single-sourced — one vendor report (Microsoft Threat Intelligence). The domain registrations, sender addresses and campaign volume are not corroborated by a second source in our corpus. Verify before enforcement actions such as domain takedowns or supplier notifications.

4. Mitigation & containment

This is a process-and-email-security problem. Containment is about stopping the lure and intercepting the payment; remediation is about hardening the payment-verification path.

P1 — within 24 hours

  • Block the campaign indicators at the mail gateway: service-nowinc[.]com, domainlify[.]net, and the nine observed sender addresses (see §5). Add a mail-flow rule flagging any mail whose Reply-To display name matches an internal executive while the Reply-To address is external — this is the campaign's core spoofing mechanic.
  • Alert accounts payable and finance teams now. Push a targeted awareness notice describing the exact lure: executive "approval" of an attached invoice, a "ServiceNow Platform — Annual Subscription" invoice, and a forwarded executive-to-vendor thread. Instruct staff that any payment-request or bank-detail-change email, regardless of apparent sender, requires out-of-band verification.
  • Sweep mail telemetry for the period 3–5 August 2026 (and since) for the sender domains/addresses in §5 and for internal-executive display names paired with external Reply-To addresses. Quarantine hits and check whether any recipient replied or engaged.
  • Freeze any in-flight payments matching the pattern: ~$50,000 ACH, ServiceNow-branded invoice, newly referenced bank details. If a transfer has been executed, engage the bank's fraud recall process immediately and preserve the original email as evidence.

P2 — within 72 hours

  • Enforce a mandatory callback control for all payment initiations and any change to beneficiary bank details: verification via a previously known phone number (never one contained in the email), performed by someone other than the person who received the request. This single control defeats the entire campaign.
  • Verify email authentication posture: SPF, DKIM and DMARC enforced at rejection (p=reject) for all owned domains, and mail-flow connectors correctly configured so externally-originated mail cannot present as internal. Microsoft specifically calls out spoof protection and connector configuration as the controls that stop this class of message pre-delivery.
  • Enable post-delivery remediation: Zero-hour Auto Purge (ZAP) in Office 365 to retroactively quarantine messages later determined malicious, and automatic attack disruption in Microsoft Defender XDR to contain in-progress attacks (Microsoft's stated mitigations for this campaign).
  • Review AP transaction history for the last 60 days for payments to previously unseen beneficiaries initiated off the back of email instructions, particularly subscription-renewal styled invoices.

P3 — within 7 days

  • Register/monitor executive and brand lookalike domains (typosquats of your own domain and of key vendors) via domain-monitoring; the actor registered service-nowinc[.]com only days before the campaign — early registration visibility is early warning.
  • Table-top the BEC scenario with finance and security jointly, using this campaign's lure structure as the inject.
  • Confirm anti-phishing policy coverage for user impersonation, domain impersonation and first-contact sender signals on finance personnel mailboxes (Microsoft's recommended detection surface for AI-themed and impersonation lures).

5. Indicators of compromise

Type Value Confidence Source
domain service-nowinc[.]com High — observed in campaign Microsoft Security Blog
domain domainlify[.]net High — observed in campaign Microsoft Security Blog
email gomez@service-nowinc[.]com High — associated with actor bank account correspondence Microsoft Security Blog
email notifications@uinsure[.]co[.]uk Medium — observed sender Microsoft Security Blog
email info@tivityhealth[.]com Medium — observed sender Microsoft Security Blog
email no-reply@lumalisboa[.]com Medium — observed sender Microsoft Security Blog
email noreply@mctci[.]com Medium — observed sender Microsoft Security Blog
email info@nuf[.]co[.]jp Medium — observed sender Microsoft Security Blog
email info@lohnsteuerhilfe-aktuell-verein[.]de Medium — observed sender Microsoft Security Blog
email info@tovimbatista[.]pt Medium — observed sender Microsoft Security Blog
email contact@eemusicclass[.]co[.]uk Medium — observed sender Microsoft Security Blog
email info@lifeones[.]com Medium — observed sender Microsoft Security Blog

The nine sender addresses are legitimate-looking addresses on unrelated domains, consistent with abuse of third-party email delivery infrastructure rather than dedicated attacker mail servers — blocking them is useful for retro-hunting but the domains themselves are not inherently malicious. All indicators are single-sourced (Microsoft); verify before enforcement.

domain  service-nowinc[.]com
domain  domainlify[.]net
email  gomez@service-nowinc[.]com
email  notifications@uinsure[.]co[.]uk
email  info@tivityhealth[.]com
email  no-reply@lumalisboa[.]com
email  noreply@mctci[.]com
email  info@nuf[.]co[.]jp
email  info@lohnsteuerhilfe-aktuell-verein[.]de
email  info@tovimbatista[.]pt
email  contact@eemusicclass[.]co[.]uk
email  info@lifeones[.]com

Behavioural indicators

Behaviour Where to observe Confidence
Sender display name matches an internal executive while Reply-To address resolves to an external domain (domainlify[.]net observed) Mail gateway logs / Defender for Office 365 High
Email body contains a short executive "approval" of an attached invoice with an offer to send a PDF version Mailbox inspection of quarantined/delivered mail High
"Forwarded" thread below the signature containing a ServiceNow-branded "Annual Subscription" invoice and a fabricated executive-to-vendor conversation Mailbox inspection High
Invoice "BILLED TO" section personalised with recipient company name and executive name Mailbox inspection High
Payment instructions referencing bank details at a financial institution not previously used by the organisation AP system / payment workflow logs Medium
HTML source shows extensive comments, structured section labelling, uniform template construction, em dashes and "==========" banner lines Raw email HTML Medium — indicative of AI-assisted templating, not conclusive

6. Detection

The sources provide no malware artefacts, file paths, registry keys or command-line indicators — the threat lives entirely in email content and mail-flow characteristics. A YARA rule is not applicable. The following Sigma-style rule targets the core mail-flow anomaly: an internal executive's display name paired with an external Reply-To domain, which is the campaign's defining spoofing mechanic.

title: Executive Display Name with External Reply-To Domain - BEC Invoice Fraud
id: 8d3f1a52-6b7c-4e29-9f41-2c5d8e0a7b31
status: experimental
description: >
  Detects inbound email where the sender or reply-to display name matches a
  known internal executive (CEO/CFO/President) while the reply-to address
  resolves to an external domain. Observed in the AI-assisted executive
  impersonation and ServiceNow invoice fraud campaign reported by Microsoft
  Threat Intelligence, September 2026. Reference:
  https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/
references:

  - https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/
tags:

  - attack.execution
  - attack.t1566
  - attack.t1656
  - attack.t1657
logsource:
  product: microsoft_365
  service: threat_management
  category: email_gateway
detection:
  selection_display:
    SenderDisplayName|contains:

      - 'CEO'
      - 'CFO'
      - 'President'
  filter_internal:
    SenderDomain: '%internal_domains%'
  condition: selection_display and not filter_internal
  replyto_external:
    ReplyToDomain|endswith:

      - 'domainlify.net'
      - 'service-nowinc.com'
  condition: selection_display and not filter_internal and replyto_external
falsepositives:

  - Legitimate third-party services sending on behalf of executives with matching display names
  - Marketing or notification platforms using executive names in sender display
level: high

Note for engineering: the replyto_external block lists the two campaign-observed domains; for broader coverage, generalise to "ReplyTo domain not in internal domains AND ReplyTo domain not equal to sender domain". The generic executive-display-name condition should be tuned against your own environment to suppress benign third-party senders.

7. Sources

  • Microsoft Security Blog — Protecting organizations from AI-assisted executive impersonation and invoice fraud — https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/ — 2026-09-10
  • Microsoft Threat Intelligence Blog — Detect and disrupt AI-themed attacks with Microsoft Defender — https://www.microsoft.com/en-us/security/blog/2026/09/10/detect-and-disrupt-ai-themed-attacks-with-microsoft-defender/ — 2026-09-10 (context on AI-themed lure trends and Defender anti-phishing capabilities; not the primary source for this campaign's IOCs)

8. Adverse Trace position

This is a high-volume, low-technical-sophistication financial fraud campaign whose effectiveness comes from narrative layering — executive impersonation, vendor branding, a personalised fake invoice and a forged executive thread — plausibly accelerated by generative AI in template production. Severity for EMEA financial services clients is medium: there is no exploit, no malware and no data compromise, but the direct loss potential (~$50,000 per successful transfer, with destination accounts varying per target) and the fact that the fraud defeats purely technical controls make payment-process discipline the decisive factor. The campaign's targeting was 87.7% US-based, but the technique is trivially portable to EMEA accounts payable teams and SEPA/SWIFT payment flows. Attribution is unconfirmed — Microsoft names no actor and no MITRE ATT&CK group profile exists in our verified reference data; the AI-assistance finding is an assessed indicator set, not a proven fact. All campaign detail is single-sourced to Microsoft; we will monitor for corroborating reporting from other vendors and for EMEA-specific variants before raising confidence. Clients should act on §4 P1/P2 immediately: the controls that stop this — display-name/Reply-To mismatch detection and out-of-band payment callbacks — are cheap, fast and effective against the entire BEC class, not just this campaign.


Read the original source →

Published via PulseTrace — Adverse Trace threat intelligence.

Post this to LinkedIn
Formatting is converted automatically — headings, bullets, a link back & hashtags. Paste straight in.
J
Jeff Davies