top of page

🚨 AI-Assisted CEO Scam Blasts More Than 1 Million Fake Invoice Emails

Writer: AigiShield
AigiShield
6 days ago
3 min read

VERIFIED EMERGING SCAM ALERT

Report date: September 15, 2026

Scam type: AI-assisted executive impersonation / business email compromise / fake invoice and ACH payment fraud

What happened

Microsoft Security has disclosed a large-scale financial fraud campaign in which criminals impersonated CEOs and other senior executives, fabricated invoices and fake forwarded email conversations, and tried to persuade company finance teams to send fraudulent ACH payments of nearly $50,000. Microsoft detected more than one million scam emails between August 3 and August 5, 2026, and says 87.7% of the campaign targeted users in the United States.

Microsoft reported multiple indicators consistent with generative AI being used to help construct the campaign templates. The attackers combined executive impersonation, vendor branding, detailed invoices and fabricated email threads into one believable story rather than relying on a simple one-line payment request.

How the scam works

  • Attackers research a company, its executives and employees who handle payments.

  • They register lookalike impersonation domains and use third-party email delivery infrastructure to send the messages.

  • The email appears to come from a CEO, CFO, president or other senior executive and requests payment for a supposed business expense.

  • A professional-looking invoice uses the branding of a real vendor. In Microsoft's observed campaign, criminals impersonated ServiceNow; the invoices were fraudulent and were not issued by ServiceNow.

  • Fake forwarded messages between executives are included beneath the invoice to make it appear that the purchase has already been discussed and approved.

  • The employee is instructed to send an ACH or bank transfer to an account controlled by the criminal.

Who is being targeted

The campaign primarily targets businesses and the employees who can approve or process payments, including accounts-payable staff, bookkeepers, controllers and finance personnel. Microsoft says organizations in IT services and business advisory, consumer goods and other industries were among those targeted. Small and midsize businesses should take the warning seriously as well: the FBI says business email compromise affects organizations of all sizes.

Warning signs

  • An executive unexpectedly asks you to pay an invoice or change normal payment procedures.

  • The request is urgent, confidential or discourages normal verification.

  • The sender display name looks correct but the actual email domain or reply-to address is slightly different.

  • A detailed invoice or convincing email thread is presented as proof that a payment was already authorized.

  • Banking instructions are new or different from those previously used by the vendor.

  • The message appears unusually polished. Good grammar is no longer evidence that an email is legitimate; AI can help criminals create professional-looking messages.

What consumers and businesses should do

  • Do not approve an unexpected payment based solely on an email, invoice or forwarded email conversation.

  • Verify significant payment requests through a second channel. Call the executive or vendor using a phone number you already know or independently locate — never a number supplied in the suspicious email.

  • Require multi-person approval or other independent verification for large transfers and changes to vendor banking information.

  • Inspect the full sender and reply-to addresses, not just the displayed name.

  • If money has already been sent, contact your financial institution immediately and ask it to contact the receiving institution. Report business email compromise to the FBI's Internet Crime Complaint Center at IC3.gov.

Why this development matters

Business email compromise is not new, but this campaign shows a significant evolution in scale and presentation. More than a million messages were sent in roughly three days, most to U.S. recipients, while the criminals layered executive impersonation, a recognizable vendor, a detailed invoice and fabricated internal correspondence into the same lure. Generative AI can make those narratives faster to produce, more personalized and harder to dismiss because of awkward wording or obvious mistakes.

For AigiShield readers, the key lesson is simple: a professional-looking invoice, an executive's name and a believable email history are evidence that can be fabricated. Independent verification is what matters.

Sources

Source classification: Verified Emerging Scam Alert. The newly documented campaign comes from Microsoft Security threat research rather than a newly issued U.S. government warning. The FBI independently confirms the underlying business-email-compromise tactics and recommended payment-verification protections.

AigiShield reminder

Think it might be a scam? Let AigiShield check it out for you.

Think Before You Click. Verify Before You Trust.

 
 
 

Recent Posts

See All

Comments


bottom of page