cd /news/artificial-intelligence/here-come-the-ai-generated-bec-scams · home topics artificial-intelligence article
[ARTICLE · art-129225] src=decipher.sc ↗ pub= topic=artificial-intelligence verified=true sentiment=↓ negative

Here Come the AI-Generated BEC Scams

Microsoft Security Research uncovered a business email compromise campaign that delivered more than a million phishing messages to enterprise targets between Aug. 3 and Aug. 5, 2026, with about 87.7 percent of targeted organizations in the United States. The attackers used AI-assisted email generation, executive impersonation, vendor branding, and lookalike domains registered July 31 to push accounts payable departments into authorizing ACH payments of nearly $50,000 per attempt. Microsoft said the campaign layered executive impersonation, fabricated invoices, and fake forwarded email threads into a unified narrative intended to reduce recipient skepticism.

read3 min views1 publishedSep 14, 2026
Here Come the AI-Generated BEC Scams
Image: source

Messages delivered through legitimate third-party email infrastructure had C-suite sender display names, custom signatures, and direct approval notes.

September 14, 2026 | 2 min read

Microsoft Security Research has uncovered a high-volume business email compromise (BEC) campaign that delivered more than a million phishing messages to enterprise targets between Aug. 3 and Aug. 5.

Approximately 87.7 percent of the targeted organizations were located in the United States, across IT services, business advisory, and consumer goods sectors. The attackers combined executive impersonation, vendor branding, lookalike infrastructure, and AI-assisted email generation to trick accounts payable departments into authorizing Automated Clearing House (ACH) payments of almost $50,000 per attempt.

The attack chain relied on pre-registered infrastructure, including domains like service-nowinc[.]com and domainlify[.]net acquired on July 31 to impersonate third-party vendors and C-suite executives. Messages delivered through legitimate third-party email infrastructure had C-suite sender display names, custom signatures, and direct approval notes pointing to an embedded, highly detailed invoice for a fake ServiceNow annual subscription. To reinforce credibility, the body contained a fake forwarded email thread simulating an exchange between the victim company's CEO and ServiceNow leadership regarding invoice processing and implementation details.

“Unlike traditional invoice scams that rely on a single social engineering lure, this campaign layered executive impersonation, vendor branding, fabricated invoices, and supporting email conversations into a unified narrative intended to reduce recipient skepticism,” Microsoft’s analysis says.

“The threat actor impersonated executive team members (such as a CEO, CFO, President) of multiple targeted companies, attempting to convince accounts payable departments of the same companies to process an ACH payment of nearly $50,000. More specifically, the CEOs were impersonated in multiple places in the email such as in the sender display name, reply-to display name, and in the email signature.”

BEC scams have become increasingly difficult to identify and defend against in recent years, and the rise of generative AI and other tools to create synthetic content has only compounded the problem.

Microsoft researchers saw several signs that generative AI was used during email template engineering. Code analysis of the underlying HTML showed extensive section comments, structured element labeling, highly uniform layout syntax across distinct target organizations, and distinctive formatting artifacts such as em dashes and repeated ASCII banner lines. Despite the visual complexity of the rendered lure, the underlying invoice layout was static while target organization metadata was programmatically swapped.

The Microsoft analysis showed key anomalies that identified the fraudulent nature of the messages. Most notably, the "forwarded" conversation blocks lacked standard MIME transit headers found in genuine email forwards, and nested thread responses were left-aligned rather than visually indented. Furthermore, logical contradictions were present in the lure text, such as signature instructions advising recipients not to CC the sender directly contradicting the main thread's message history.

“Microsoft observed the use of multiple financial institutions across samples, indicating that payment destinations may vary between targets. Certain parts of the invoice are personalized to the recipient. Specifically, the “BILLED TO” section has the recipient company name and executive name,” the company’s analysis says.

Dennis Fisher is an award-winning journalist and author. He is one of the co-founders of Decipher and Threatpost and has been writing about cybersecurity since 2000. Dennis enjoys finding the stories behind the headlines and digging into the motivations and thinking of both defenders and attackers. He is the author of 2.5 novels and once met Shaq. Contact: dennis at decipher.sc.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @microsoft security research 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/here-come-the-ai-gen…] indexed:0 read:3min 2026-09-14 ·