ZeroHour
Story · 2 sources · 2 articlesfirst updated ()

Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments

mediumPhishing & fraudexploited in the wildimportance 68
What's new: New story established (first merged summary): Microsoft disclosed a 1M+ message AI-assisted BEC campaign (August 3–5, 87.7% US-targeted) using executive impersonation and fake ServiceNow invoices to solicit ~$50,000 ACH payments, with no compromise of ServiceNow itself.
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Microsoft tracked a BEC campaign of over one million AI-assisted emails, sent August 3–5 with 87.7% targeting US recipients, impersonating executives and carrying fake ServiceNow invoices to induce ~$50,000 ACH payments to attacker-controlled accounts.

Microsoft analysts detected a business email compromise (BEC) campaign that delivered more than one million messages between August 3 and 5, with 87.7% of the volume targeting US recipients. The emails impersonated CEOs, CFOs, and presidents and embedded fabricated ServiceNow-branded subscription invoices directing accounts-payable staff to authorize ACH transfers of roughly $50,000 to attacker-controlled accounts. Attackers used lookalike domains such as service-nowinc[.]com — registered July 31, days before delivery — in sender and reply-to addresses, along with third-party delivery accounts. No malicious attachments or malware were used, and Microsoft found no evidence that ServiceNow or the named companies were compromised. Researchers inferred AI-assisted template creation from verbose HTML/CSS artifacts, structured templates, verbose HTML comments, uniform formatting, and inconsistent forwarded-message headers. Defenders were urged to verify payment requests out-of-band and enforce SPF/DKIM/DMARC.

  • Over 1 million BEC messages detected by Microsoft, sent August 3–5
  • 87.7% of campaign volume targeted US recipients
  • Emails impersonated CEOs, CFOs, and presidents with fake ServiceNow-branded subscription invoices
  • Fraudulent ACH payment requests were for roughly $50,000 to attacker-controlled accounts
  • Lookalike domain service-nowinc[.]com, registered July 31, was used in sender and reply-to addresses; third-party delivery accounts were also used
  • No malicious attachments or malware were used in the campaign
  • Microsoft found no evidence that ServiceNow or the named companies were compromised
  • AI-assisted template creation was inferred from verbose HTML/CSS comments, uniform formatting, and inconsistent forwarded-message headers

Coverage timeline

  1. · 4d ago
    GBHackers· 68
    Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.

    Microsoft tracked a million-message AI-assisted BEC campaign impersonating executives with fake ServiceNow invoices to steal ~$50,000 ACH payments.

  2. · 4d ago
    Cyber Security News· 45
    Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments

    A BEC campaign sent over one million fake CEO invoice emails, mostly to US firms, urging ~$50,000 ACH transfers to attacker accounts.