Ground Truth.
AI, checked against the source.

News · 2026-09-13

Microsoft says a million CEO-impersonation invoice emails, built with signs of AI help, went out in three days

Microsoft Security Research reported on 10 September 2026 that a single fraud campaign sent more than one million emails in three days impersonating companies' own chief executives, asking accounts-payable staff to pay invoices of nearly $50,000. Microsoft found several indicators that the attackers used generative AI to build the email templates, an example of AI making classic business email fraud cheaper to run at industrial scale.

Key facts

An old scam, new tooling

Business email compromise is one of the most profitable forms of cybercrime because it needs no malware. An attacker pretends to be someone with authority, usually the boss or a trusted supplier, and asks an employee to move money. Its traditional weak point has been effort: convincing, personalised emails take time to write, and sloppy ones get caught.

Microsoft's report describes a campaign that removed much of that effort. The attacker impersonated the chief executives of many target companies at once, writing to each company's own accounts-payable department. According to Microsoft, the actor tried “to convince accounts payable departments of the same companies to process an Automated Clearing House (ACH) payment of nearly $50,000.”

How the con worked

To make each request look routine, the emails included what appeared to be a forwarded thread between the chief executive and ServiceNow, a large software vendor, along with a fabricated invoice. The scene the email paints is familiar to any finance clerk: the boss has already agreed a purchase with a well-known supplier and just needs the payment processed. Replies were routed to a lookalike address controlled by the attacker.

Microsoft is clear that the named vendor was a prop, not a victim: “Microsoft found no evidence that the legitimate organizations referenced in the lures, including ServiceNow, were compromised or involved in the activity.”

The AI fingerprints

What moved this from routine fraud report to AI-security story is the template analysis. Microsoft “observed several indicators consistent with AI-assisted template development,” including “extensive HTML comments, structured section labeling, and highly uniform template construction.” The screenshots show verbose comments explaining each section of the email's code, which Microsoft calls a characteristic commonly observed in AI-generated code, plus em dashes and banner-style dividers.

Think of it as a burglar who leaves behind a store-bought lock-pick set still in its labelled packaging. The tool does not prove who did the job, but it shows how the job was done: a template assembled quickly by a coding assistant, then stamped out a million times with different company names.

Why it matters

AI's biggest near-term effect on crime may not be exotic new attacks but making effective old ones cheap. Personalising a CEO impersonation for thousands of companies used to require a team; generating and debugging the templates is now a short session with an AI tool. That fits a pattern Ground Truth has tracked, from Google warning that attackers have moved from prompting to autonomous agents to Anthropic reporting that AI-run hacking has spread to every kind of attacker it tracks.

It also changes the defence. Staff have long been trained to spot scams by bad grammar and odd formatting. Polished, uniform emails remove those clues, so the protection has to come from process: confirming payment changes by phone using a known number, and requiring a second approver for unexpected transfers.

The caveat

Microsoft is careful not to overclaim: “While these indicators suggest generative AI involvement, they do not independently establish the extent to which AI generated campaign content.” The actor is not named, Microsoft does not report how many payments, if any, were made, and stylistic signals like em dashes are weak evidence on their own. The campaign is also a month old; the report is new.


Primary source, verified: read the paper →

Key questions

How did Microsoft conclude AI was involved in the invoice fraud campaign?

From the email templates, which contained extensive explanatory HTML comments, structured section labels, highly uniform construction, em dashes and banner-style dividers, traits Microsoft associates with AI-generated code. Microsoft says these suggest AI involvement but do not establish its extent.

Was ServiceNow hacked in this campaign?

No. The attackers impersonated ServiceNow in a fabricated email thread, and Microsoft says it found no evidence that ServiceNow or any other legitimate organisation referenced in the lures was compromised or involved.

How can finance teams protect themselves against CEO impersonation invoice fraud?

The durable defence is process rather than spotting bad writing: verify any new payment request through a separate, known channel before paying, and treat urgent requests that bypass normal approval as suspicious, since AI-polished emails remove the usual typos and awkward phrasing.
Cite this

APA

Ground Truth. (2026, September 13). Microsoft says a million CEO-impersonation invoice emails, built with signs of AI help, went out in three days. Ground Truth. https://groundtruth.day/news/microsoft-says-a-million-ai-assisted-ceo-impersonation-emails-went-out-in-three-days.html

BibTeX

@misc{groundtruth:microsoft-says-a-million-ai-assisted-ceo-impersonation-emails-went-out-in-three-days,
  title  = {Microsoft says a million CEO-impersonation invoice emails, built with signs of AI help, went out in three days},
  author = {{Ground Truth}},
  year   = {2026},
  month  = {sep},
  url    = {https://groundtruth.day/news/microsoft-says-a-million-ai-assisted-ceo-impersonation-emails-went-out-in-three-days.html}
}

Topics: cybersecurity · ai-security · business-email-compromise · phishing · fraud · microsoft

Comments are replies to this story on Bluesky — reply with any Bluesky account to join in.