ZeroHour

Search: “invoice fraud”

10 stories in the last 30d

Protecting organizations from AI-assisted executive impersonation and invoice fraud

Microsoft tracked a campaign of over one million AI-crafted CEO-impersonation emails seeking ~$50,000 ACH payments with fabricated ServiceNow invoices.

Between August 3 and 5, Microsoft detected a campaign of more than one million fraud emails, 87.7% of them targeting US enterprise users, sent through multiple third-party email delivery service accounts. The actor impersonated CEOs, CFOs, and presidents of targeted companies, urging accounts payable staff to process an ACH payment of nearly $50,000. Lures layered executive impersonation, lookalike domains, a fabricated ServiceNow 'Annual Subscription' invoice personalized to the recipient, and forged forwarded email threads; Microsoft found no evidence ServiceNow or the referenced executives were compromised. Microsoft observed indicators consistent with generative AI-assisted template creation, while leftover inconsistencies such as missing forwarding headers and mismatched display names gave defenders detection cues.

Microsoft Security Blog · 6d agoPhishing & fraud1

Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.

Microsoft tracked a million-message AI-assisted BEC campaign impersonating executives with fake ServiceNow invoices to steal ~$50,000 ACH payments.

Microsoft detected over one million messages in a BEC campaign running August 3-5, using AI-assisted phishing templates, executive impersonation, and fabricated ServiceNow subscription invoices to trick finance teams into authorizing fraudulent ACH payments of roughly $50,000. The US received 87.7% of volume. Attackers used lookalike domains like service-nowinc[.]com registered just days before delivery, with no compromise of ServiceNow itself. Telltale signs included verbose HTML comments, uniform formatting, and inconsistent forwarded-message headers.

GBHackersupdated · 6d agofirst · 6d agoPhishing & fraud in the wild 2 sources

N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security

N0va phishkit targets US and EU organizations with trusted-brand lures, capturing tokens via legitimate authentication flows to gain SSO access to corporate resources.

The N0va phishing kit targets organizations in government, technology, consulting, and healthcare across North America and Europe with lures impersonating Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign. Victims are guided through legitimate authentication flows, including device code phishing, after which N0va captures access and refresh tokens and abuses token-exchange or device-registration mechanisms to establish SSO access. ANY.RUN tracks the campaign via a characteristic /api/verification/init URL pattern and demonstrates detection in its interactive sandbox.

The Hacker News · 1d agoPhishing & fraud in the wild 2 sources3

Phishing 3.0: The Fight Moves to Agent Versus Agent

Agentic AI transforms phishing economics, enabling personalized multi-channel attacks with deepfakes like the $25M Arup deepfake heist.

The article argues phishing has evolved through three stages: from malicious content, to intent-based BEC, to AI-powered multi-channel campaigns where attacker agents autonomously conduct reconnaissance and generate tailored lures. The widely reported Arup case saw a deepfake video call impersonating colleagues convince an employee to approve transfers worth roughly $25 million. An Osterman Research study of 128 security leaders found 88% experienced trust-undermining incidents, while Microsoft 365 EOP and Google Workspace were measured missing hundreds of phishing messages per 100 mailboxes monthly. The author argues defenders must adopt their own agents to match attacker speed.

The Hacker News · 29d agoPhishing & fraud2

AI is making fraud harder to spot and identity harder to prove

Experian's 2026 report finds AI-generated scams, deepfakes and synthetic identities spreading across digital channels, pushing businesses toward adaptive identity verification and 'Know Your Agent' checks.

Experian's 2026 US Identity & Fraud Report, based on consumer and business surveys, found 60% of consumers aware of AI-generated image/video scams, 53% of AI phishing, and 47% of deepfake voice impersonation. 80% of US businesses already use machine learning or generative AI in fraud management, while AI chatbot account openings rose from 16% in 2025 to 27%. The report highlights adaptive authentication, behavioral biometrics, and emerging 'Know Your Agent' controls as AI agents begin acting on behalf of customers.

Help Net Security · 28d agoPhishing & fraud

Microsoft sees some new wrinkles in invoice-scam emails

Microsoft researchers observed a BEC invoice scam sending 1M+ AI-assisted emails impersonating executives and ServiceNow to request ~$50,000 payments.

Microsoft researchers tracked a campaign of more than one million invoice-scam emails launched in early August, with about 88% of targets in the United States. Attackers impersonated top executives and ServiceNow, fabricating forwarded email threads and invoices to convince accounts payable teams to send payments of nearly $50,000. Microsoft found indicators such as extensive HTML comments and highly uniform template construction consistent with AI-assisted campaign development, though it could not independently establish how much content AI generated.

The Record · 5d agoPhishing & fraud

Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters

VBSpam Q3 2026 test shows phishers abusing DKIM-aligned domains, Amazon SES, and multi-stage URL cloaking to defeat email filters.

Virus Bulletin's Q3 2026 VBSpam test (AMTSO-LS1-TP207) found phishing campaigns moving payloads past the email itself via browser-fingerprinting gates, redirect chains, and hidden POST requests. Examples include a Dutch McAfee/TotalAV scareware renewal scam, a German overdue-payment Web3 fraud delivered via Amazon SES from DKIM-aligned moolaah.com, and Romanian BCR PSD2 credential phishing embedding IPv6-mapped URLs resolving to 103.193.179.223. Net at Work NoSpamProxy ranked first with a 99.995 score while open-source Rspamd caught only 62.55% of phishing mail.

GBHackers · 2d agoPhishing & fraud in the wild 2 sources

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Microsoft details two campaigns: million-email CEO impersonation ACH fraud and passkey-themed vishing that hijacks Microsoft cloud accounts for data theft and extortion.

Microsoft disclosed a campaign that sent over one million CEO-impersonation scam emails between August 3-5, 2026, targeting U.S. accounts payable departments with fake ServiceNow subscription invoices to induce ACH transfers, using generative AI to tailor templates. A second campaign detected since May 2026 uses passkey/MFA-themed voice phishing posing as the IT help desk, redirecting victims via SMS to counterfeit Microsoft sign-in pages and adversary-in-the-middle or device-code flows to hijack accounts. Post-compromise activity includes adding attacker-controlled authentication methods, high-volume Microsoft Graph activity, SharePoint and OneDrive downloads, and mailbox collection via REST APIs. Microsoft attributes initial access to Storm-3121 (linked to ShinyHunters and Falcon extortion) and Storm-3032 (UNC6671, a BlackFile splinter operating the Helix extortion brand).

The Hacker News · 4d agoPhishing & fraud in the wild2

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

NovaCookies AitM phishing kit, a Sneaky 2FA variant, uses genuine Docusign lures to steal Microsoft 365 sessions at hundreds of organizations.

Island disclosed NovaCookies, a $320/month adversary-in-the-middle phishing-as-a-service platform that relays Microsoft 365 sign-ins through attacker infrastructure to capture credentials, MFA codes, and authenticated sessions. Campaigns abuse genuine Docusign envelopes and Microsoft/Google redirect hops so each step looks legitimate, with lure domains on .vu and alternating-case labels such as PwPt-sHaRe. Proofpoint assesses NovaCookies as a Sneaky 2FA variant with added flows for Okta and Entra domains federated to GoDaddy, and a fully managed PhaaS model. It has targeted hundreds of organizations in the U.S., U.K., Canada, Germany, Israel, and the U.A.E., and is advertised via Telegram with anti-analysis checks like a Cloudflare gate.

The Hacker News · 16d agoPhishing & fraud

Detect and disrupt AI-themed attacks with Microsoft Defender

Microsoft Threat Intelligence reports criminal campaigns impersonating ChatGPT, Copilot, Claude, and DeepSeek in phishing, AiTM, and malvertising attacks reaching 100,000 emails daily.

Microsoft Threat Intelligence observed a growing set of campaigns that abuse trust in popular AI brands: a ChatGPT-themed phishing campaign sent up to 100,000 emails in one day to steal payment card data, and a Claude-themed campaign used adversary-in-the-middle techniques to harvest credentials and access tokens. Other campaigns included malvertising for a fake AI Windows plugin delivering the Vidar stealer and fraudulent DeepSeek installers distributed via GitHub. Initial access broker Storm-3075 used AI-themed malvertising to distribute payloads for multiple downstream actors, and Microsoft notes the AI services themselves were not compromised. Microsoft also details Defender protections such as Safe Links, Safe Attachments, and attack disruption against these multi-stage lures.

Microsoft Security Blog · 6d agoPhishing & fraud in the wild1