ZeroHour
GBHackerspublished ()ingested Mayura Kathir
Part of a story covered by 2 sources: “Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments” — merged summary and timeline →

Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.

mediumPhishing & fraud exploited in the wildimportance 68
AI summary · glm-5.3-flash

Microsoft tracked a million-message AI-assisted BEC campaign impersonating executives with fake ServiceNow invoices to steal ~$50,000 ACH payments.

Microsoft detected over one million messages in a BEC campaign running August 3-5, using AI-assisted phishing templates, executive impersonation, and fabricated ServiceNow subscription invoices to trick finance teams into authorizing fraudulent ACH payments of roughly $50,000. The US received 87.7% of volume. Attackers used lookalike domains like service-nowinc[.]com registered just days before delivery, with no compromise of ServiceNow itself. Telltale signs included verbose HTML comments, uniform formatting, and inconsistent forwarded-message headers.

  • 1M+ messages detected; US received 87.7% of volume
  • Impersonated CEOs/CFOs with embedded fake ServiceNow invoices
  • AI-assisted template creation inferred from verbose HTML/CSS artifacts
  • Lookalike domain service-nowinc[.]com registered July 31
  • Defenders urged to verify payments out-of-band and enforce SPF/DKIM/DMARC

Indicators of compromiseAll →

TypeIndicatorContext
domaindomainlify.nett in the fake invoice as a contact address. Another domain, domainlify[.]net, was used in Reply-To fields. The short preparation perio
domaineemusicclass.co.ukuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email address Sender email address
domainlifeones.cominfo@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email address Sender email address used to send out email
domainlohnsteuerhilfe-aktuell-verein.deumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk inf
domainlumalisboa.comications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhil
domainmctci.comk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]
domainnuf.co.jpth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbati
domainservice-nowinc.comonsumer goods’ and others (Source : Microsoft). One domain, service-nowinc[.]com, was registered on July 31, shortly before the phishing a
domaintivityhealth.comated with bank account notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]
domaintovimbatista.ptnuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email
domainuinsure.co.ukss Email address associated with bank account notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com norep
Full article959 words · extracted from gbhackers.com · click to collapse

Threat actors are using AI-assisted phishing templates, executive impersonation, fake ServiceNow invoices, and fabricated email threads to pressure finance teams into authorizing fraudulent ACH payments worth nearly $50,000.

Microsoft detected more than one million messages in the campaign, demonstrating how business email compromise (BEC) operations are becoming more polished, scalable, and difficult to spot.

The United States received 87.7% of the campaign volume, indicating a broad effort to target organizations with U.S.-based finance and accounts-payable operations.

The operation centered on executive impersonation. Attackers posed as CEOs, CFOs, and company presidents from the victim organizations themselves, using executive names in the sender display name, reply-to display name, signature block, and embedded email conversation.

The messages sought to make accounts-payable personnel believe that a senior executive had already approved an urgent invoice and expected the recipient to process the transaction.

Rather than relying on a simple payment request, the operators built a multi-layered social-engineering narrative.

The spoofed CEO email included a detailed “ServiceNow Platform Annual Subscription” invoice, complete with ServiceNow-themed branding, logos, line items, invoice metadata, payment instructions, and organization-specific details in the “Billed To” field.

However, the payment destination was a bank account controlled by the threat actor. Microsoft noted that the actor used multiple financial institutions across samples, suggesting that payment details could change by target.

The emails also contained fabricated forwarded correspondence between the impersonated executive and a purported ServiceNow president.

The staged discussion described the alleged subscription purchase, implementation process, and handling of the invoice.

This additional content was intended to preempt questions from finance employees and create the impression that the transaction had already been discussed and approved at the executive level.

Attack chain showing domain registration, executive impersonation, invoice fraud delivery (Source : Microsoft).
 Attack chain showing domain registration, executive impersonation, invoice fraud delivery (Source : Microsoft).

Microsoft stressed that ServiceNow and other legitimate organizations referenced in the messages were not compromised or involved.

Microsoft observed the campaign AI-assisted phishing, between August 3 and 5, when attackers used multiple third-party email delivery service accounts to distribute the fraud emails to enterprise users.

AI-assisted Phishing

The campaign instead relied on attacker-controlled infrastructure, fraudulent content, and lookalike domains designed to resemble trusted brands.

 Industry distribution of targeted enterprises of this campaign with ‘IT services & business advisory’ along with ‘Consumer goods’ and others (Source : Microsoft).
 Industry distribution of targeted enterprises of this campaign with ‘IT services & business advisory’ along with ‘Consumer goods’ and others (Source : Microsoft).

One domain, service-nowinc[.]com, was registered on July 31, shortly before the phishing activity began. Attackers used it to impersonate a ServiceNow executive and embedded it in the fake invoice as a contact address.

Another domain, domainlify[.]net, was used in Reply-To fields. The short preparation period between domain registration and mass delivery reflects the speed with which BEC actors can operationalize new phishing infrastructure.

Microsoft found several signs consistent with AI-assisted template creation, including verbose HTML comments, structured section labels, unusually uniform formatting, and heavily commented CSS and layout elements.

The templates also used stylistic patterns such as em dashes and banner-style separators.

Account information linked with email of impersonated domain (Source : Microsoft).
Account information linked with email of impersonated domain (Source : Microsoft).

These artifacts do not prove that generative AI authored every message or invoice.

However, they suggest that attackers may be using AI to accelerate the production of polished, reusable email templates while dynamically swapping victim-specific names, companies, and executive identities.

Microsoft observed that invoice identifiers and narrative structures were broadly consistent across samples, while organization-specific data changed from target to target.

For defenders, the key warning is that email quality is no longer a dependable security signal.

Well-written language, professional branding, and a plausible executive tone should not substitute for payment verification.

The embedded “forwarded” conversation contained several inconsistencies that can help identify the fraud. The supposed forwarded messages lacked the normal header data expected in genuine email chains.

Their formatting was also inconsistent with standard threaded email presentation, with prior messages left-aligned rather than visibly grouped or indented.

Other warning signs included display names that did not match the underlying sender address, financial lure terms such as “due bill” and “ACH Payment,” and contradictory instructions.

In one message, the impersonated CEO reportedly directed staff not to copy them on the invoice exchange; later, the same narrative suggested the CEO had directly sent and approved the invoice.

Organizations should treat executive-originated payment requests, new vendor banking instructions, and urgent invoice approvals as high-risk events.

Finance teams should independently confirm requests using a previously verified phone number, approved vendor portal, or established internal escalation channel not contact details included in the suspicious email.

Microsoft recommends configuring email authentication controls including SPF, DKIM, and DMARC; strengthening anti-phishing and spoof-protection policies; and reviewing third-party mail-flow connectors that could affect message filtering.

Organizations using Microsoft 365 should also enable Zero-hour Auto Purge, which can retroactively quarantine malicious emails after delivery as new threat intelligence becomes available.

Automatic attack disruption in Microsoft Defender access can further help contain active attacks and provide security teams time to investigate affected accounts and indicators.

The campaign shows that modern BEC is evolving from isolated spoofed messages into full fraud narratives.

AI-assisted content may make those narratives more convincing, but strict out-of-band verification remains the most important control separating a suspicious email from a $50,000 loss.

Indicators of compromise

IndicatorTypeDescription
service-nowinc[.]comDomainDomain impersonating ServiceNow
gomez@service-nowinc[.]comEmail addressEmail address associated with bank account
notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]comEmail addressSender email address used to send out emails

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Mayura Kathirhttps://gbhackers.com/

Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/ai-assisted-phishing/