Protecting organizations from AI-assisted executive impersonation and invoice fraud


Threat actors are increasingly improving their tactics to make suspicious emails look like legitimate email notifications to potential victims, deploying techniques that impersonate internally sent emails from executive team members. While this technique is not new, the adoption of AI has enabled threat actors to improve their campaign templates and construct emails tailored to their recipients. Additionally, threat actors are incorporating multiple techniques within the same email to improve the overall narrative further.

In this blog, we will discuss a recent campaign observed using third-party email delivery infrastructure to send out over a million financial fraud scam emails that displayed multiple indicators consistent with the use of generative AI during email template creation. The threat actor impersonated CEOs of multiple target companies, attempting to convince accounts payable departments of the same companies to process an Automated Clearing House (ACH) payment of nearly $50,000. To add legitimacy, the actor included a forwarded email thread (and a fabricated invoice) between the impersonated CEO and ServiceNow (which was also being impersonated).

Read more…
Source:  Microsoft News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • ShinyHunters hackers are going after Oracle systems once again

    September 29, 2026

    ShinyHunters have found a way to bypass a mitigation for a zero-day they previously exploited – so now, not only are they back to abusing the same bug, they’ve even expanded their scope to target a much larger pool of organizations. In June 2026, it was reported that ShinyHunters, the infamous data extortionists, found a Java ...

  • Dutch police arrest ‘security researcher’ in ShinyHunters probe

    September 29, 2026

    Dutch police have arrested a 24-year-old man on suspicion of involvement with the prolific ShinyHunters cybercrime group. Cops announced the arrest on Monday night and said the Amsterdam resident would appear before judges at Rotterdam District Court today (Tuesday). Officers have not named the suspect. However, a company has identified a person they believe to be the ...

  • Italy’s top bank hit by an AI messaging scam which cost it nearly €100 million

    September 29, 2026

    Cybercriminals have tricked a major Italian bank into wiring more than $100 million abroad by targeting executives with AI-powered deepfakes. Some of the money has since been recovered, but a significant portion remains unaccounted for. The target was Fideuram – Intesa Sanpaolo Private Banking, a very large Italian private-banking and wealth-management group owned by Intesa Sanpaolo. ...

  • Fake iPhone Duo preorder scam triggers DarkSword attack

    September 29, 2026

    Apple announced its first foldable iPhone on September 9, and scammers were ready to ‘deliver’ one before anyone could buy it. Most of what MalwareBytes researchers found around the launch of the iPhone Duo and iPhone 18 Pro was familiar fraud. But one fake preorder page was different. Read more… Source:  MalwareBytes Labs Sign up for the Cyber Security Review ...

  • A former US Army soldier has been sentenced to 70 months in prison for hacking telecoms companies

    September 28, 2026

    A former US Army soldier has been sentenced to 70 months in prison for hacking telecoms companies, stealing sensitive records, and trying to extort more than $1 million from his victims. Cameron John Wagenius, 22, carried out the campaign while serving on active duty. He pleaded guilty in March 2025 to unlawfully transferring confidential phone records, ...

  • Kiteworks urges customers to shut down their servers amid ‘imminent’ threat of cyberattack

    September 25, 2026

    Technology giant Kiteworks is urging customers to shut down their systems after the company received information that hackers may attempt to target them. Kiteworks (formerly Accellion), which makes tools for transferring large files and sensitive datasets over the internet, confirmed to TechCrunch that it had notified its customers about a potential threat. The news was first ...