Massive BEC Campaign Impersonates CEOs, Targets Employees with Fake Invoices
A large-scale business email compromise campaign sent over one million emails impersonating CEOs to trick employees into approving fraudulent payments.

A sophisticated business email compromise (BEC) campaign has been detected, involving the distribution of over one million emails designed to trick employees into approving fraudulent payments. The attackers impersonated senior executives, including CEOs, CFOs, and presidents, using spoofed sender details and personalized invoices to create a sense of legitimacy. This operation, which occurred between August 3rd and 5th, primarily targeted recipients in the United States, accounting for 87.7% of the campaign's reach.
The primary objective of this attack was to persuade accounts-payable staff to initiate Automated Clearing House (ACH) transfers to bank accounts controlled by the criminals. Unlike many cyberattacks that exploit software vulnerabilities or deploy malware, this campaign relied solely on social engineering and impersonation tactics. The attackers crafted a believable narrative around the payment request, making it appear as a routine internal approval, thereby aiming to bypass scrutiny that might otherwise be applied to more overtly suspicious communications.
Microsoft's analysis of the campaign revealed signs consistent with AI-assisted template development. The emails featured spoofed executive names in the display name, reply-to fields, and signatures. Below the executive's approval, recipients found a forwarded invoice, branded with ServiceNow, that included typical invoice details such as invoice numbers, dates, currency, amounts due, payment instructions, and itemized charges. The "billed-to" section was specifically tailored with the recipient company's name and an executive's name, enhancing the personalization and perceived authenticity of the request.
While the invoices appeared legitimate, several indicators suggested a fraudulent origin. The fake forwarded messages lacked standard email headers, and their alignment was inconsistent. Display names often did not match the actual sender email addresses, and subject lines contained unusual phrasing like "due bill" and "ACH Parment." These subtle discrepancies, alongside the use of lookalike domains and third-party email delivery services, were crucial in identifying the scam.
The attackers registered domains that closely resembled legitimate ones, such as a ServiceNow-style domain used in the fake president's email address and invoice contact details. Another lookalike domain was employed in the Reply-To field, further blurring the lines between legitimate vendor correspondence and the fraudulent request. This strategic use of domain impersonation was key to the campaign's deceptive effectiveness.
Researchers observed extensive use of HTML comments, highly structured sections, and consistent template construction within the campaign's emails. These characteristics are compatible with the use of generative AI in drafting the malicious content, allowing attackers to efficiently produce targeted and convincing material. While direct proof of AI's involvement in content creation is difficult, the observed patterns suggest automated drafting played a significant role in scaling the operation.
To mitigate such threats, organizations are advised to implement robust payment verification processes that go beyond email-based approvals. Verifying requests for bank detail changes or urgent transfers through independent channels, such as a known phone number, is critical. Additionally, configuring email authentication protocols like SPF, DKIM, and DMARC, alongside implementing spoof protection and filtering, can significantly enhance defenses. Training finance personnel to meticulously inspect sender addresses and message histories is also paramount.
Ultimately, a layered security approach is essential. This includes enabling mail-flow rules for post-delivery removal or quarantine, establishing clear channels for employees to report suspected fraud, and monitoring suspicious domains and sender addresses. A brief verification pause before processing payments can prevent significant financial losses, underscoring the importance of vigilance and established security protocols in combating sophisticated BEC attacks.