CyberSecurityNews

Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments


A large email fraud campaign used fake CEO messages and invoices to push employees toward payments of nearly $50,000. The operation did not rely on a malicious attachment or software flaw. Instead, it used ordinary email to deliver a scam.

The attackers sent over one million messages to users between August 3 and 5. Most recipients were in the United States, representing 87.7% of the campaign.

Their objective was to persuade accounts-payable staff to approve an Automated Clearing House, or ACH, transfer to criminal-controlled bank accounts.

Microsoft said in a report shared with Cyber Security News (CSN) that analysts identified signs consistent with AI-assisted template development.

It was a business email compromise campaign using impersonation, fake supplier material, and personalised messages, not malware. The scale matters because the messages resembled routine internal approvals, where speed can be valued over scrutiny.

Finance teams received a believable request backed by an executive and vendor. Microsoft found no evidence that organisations named in the lures, including ServiceNow, were compromised or involved.

Hackers Impersonate CEOs in 1 Million Emails

The emails copied the identities of senior leaders, including CEOs, CFOs, and presidents, at targeted companies. A spoofed CEO appeared in the sender display name, reply-to display name, and signature. The short message approved an invoice and told recipients to request a PDF if needed.

Attack chain (Source – Microsoft)

That familiar tone can make this fraud difficult to spot. Unlike a basic invoice scam, the actor built a complete story around the payment request. As business email compromise attacks grow, criminals use trusted roles and everyday financial processes to lower a recipient’s guard.

Below the executive signature, victims saw a forwarded annual-subscription invoice carrying ServiceNow branding. It included invoice numbers, dates, currency, an amount due, payment details, and itemised charges.

The billed-to area was tailored with the recipient company’s name and an executive’s name, adding a personal touch to the deception. The invoice instructed staff to make a bank transfer, while destination accounts belonged to the attacker.

Microsoft observed multiple financial institutions across samples, suggesting payment routes could differ by target. The criminals inserted a supposed executive exchange to make the purchase appear approved.

Several warning signs remained. The fake forwarded messages lacked normal headers, and they were left aligned rather than visually grouped.

Top industry distribution of targeted enterprises (Source - Microsoft)
Top industry distribution of targeted enterprises (Source – Microsoft)

Display names did not always match sender addresses, while subjects used odd phrases, such as “due bill” and “ACH Parment.” These details remain valuable checks alongside recent phishing threat reporting.

AI Templates Amplify Invoice Fraud

Before sending the messages, the actor registered lookalike domains and used third-party delivery accounts to distribute the campaign.

One ServiceNow-style domain appeared in the fake president’s address and invoice contact details; another was used in the Reply-To field. This made a fraudulent request look like vendor correspondence.

Researchers also saw extensive HTML comments, highly structured sections, and consistent template construction, all signs compatible with generative-AI assistance.

These observations do not prove how much content AI created. They do show how automated drafting can help criminals produce target-specific material, a concern raised by AI phishing defense guidance.

Spoofed ServiceNow invoice (Source - Microsoft)
Spoofed ServiceNow invoice (Source – Microsoft)

Organisations should make payment verification a process, not a judgment call. Requests to change bank details, approve invoices, or send urgent transfers should be checked through a known phone number or another independent channel.

Staff should never rely only on a reply to the email that made the request. Defenders should also configure email authentication, including SPF, DKIM, and DMARC, and apply spoof protection and filtering.

Teams can review mail-flow settings, enable post-delivery removal or quarantine where available, and train finance personnel to inspect addresses and message history.

Coverage of finance mailbox takeover fraud shows why a layered approach matters when a convincing email can trigger a costly payment. Finally, organisations should give finance employees a route to report suspected fraud.

A short verification pause can stop a transfer before money leaves the business. Monitoring the domains and sender addresses below can help find related messages and block future attempts.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
Domainservice-nowinc[.]comDomain impersonating ServiceNow
Email addressgomez@service-nowinc[.]comEmail address associated with a bank account
Email addressnotifications@uinsure[.]co[.]ukSender email address used to send campaign emails
Email addressinfo@tivityhealth[.]comSender email address used to send campaign emails
Email addressno-reply@lumalisboa[.]comSender email address used to send campaign emails
Email addressnoreply@mctci[.]comSender email address used to send campaign emails
Email addressinfo@nuf[.]co[.]jpSender email address used to send campaign emails
Email addressinfo@lohnsteuerhilfe-aktuell-verein[.]deSender email address used to send campaign emails
Email addressinfo@tovimbatista[.]ptSender email address used to send campaign emails
Email addresscontact@eemusicclass[.]co[.]ukSender email address used to send campaign emails
Email addressinfo@lifeones[.]comSender email address used to send campaign emails
Domaindomainlify[.]netNewly registered domain used in the Reply-To address

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.



Source link