EXECUTIVE SUMMARY:
A campaign has used AI-assisted email templates, executive impersonation, fabricated invoices, and lookalike domains to deceive enterprise finance personnel. The campaign distributed more than one million emails designed to appear as legitimate payment requests from company executives and trusted vendors, with the objective of convincing accounts payable teams to authorize fraudulent bank transfers. The emails combined multiple social engineering elements to create a convincing narrative and reduce suspicion among recipients.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
A campaign has used AI-assisted email templates, executive impersonation, fabricated invoices, and lookalike domains to deceive enterprise finance personnel. The campaign distributed more than one million emails designed to appear as legitimate payment requests from company executives and trusted vendors, with the objective of convincing accounts payable teams to authorize fraudulent bank transfers. The emails combined multiple social engineering elements to create a convincing narrative and reduce suspicion among recipients.[emaillocker id="1283"]
The campaign leveraged third-party email delivery infrastructure, attacker-controlled domains, spoofed executive identities, and fabricated vendor communications. Fraudulent messages impersonated CEOs, CFOs, and other executives while requesting approval for invoices and payments through ACH transfers. Attackers created lookalike domains and included fabricated invoices containing legitimate-looking branding, recipient-specific company information, payment details, and fake forwarded email conversations. Indicators of AI-assisted template development included extensive HTML comments, structured sections, consistent formatting, and repeated invoice structures with customized victim information. The campaign also used mismatched sender details, suspicious reply-to addresses, financial lure terminology, and inconsistencies in fabricated email threads to support the deception.
It demonstrates how AI-assisted content generation can enhance executive impersonation and business email compromise by producing convincing financial fraud communications at scale. Organizations should strengthen email authentication and anti-phishing controls, monitor executive and vendor impersonation attempts, verify payment requests through independent communication channels, and apply additional scrutiny to invoices and unusual bank-transfer instructions. Security teams should also monitor newly registered lookalike domains and suspicious email infrastructure associated with fraudulent payment campaigns.
THREAT PROFILE:
| Tactic | Technique Id | Technique | Sub-technique |
| Initial access | T1195.002 | Supply Chain Compromise | Compromise Software Supply Chain |
| Initial access | T1566.001 | Phishing | Spearphishing Attachment |
| Initial access | T1566.002 | Phishing | Spearphishing Link |
| Execution | T1059.006 | Command and Scripting Interpreter | Python |
REFERENCES:
The following reports contain further technical details:
https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/