Messages delivered through legitimate third-party email infrastructure had C-suite sender display names, custom signatures, and direct approval notes.
September 14, 2026 | 2 min read
Microsoft Security Research has uncovered a high-volume business email compromise (BEC) campaign that delivered more than a million phishing messages to enterprise targets between Aug. 3 and Aug. 5.
Approximately 87.7 percent of the targeted organizations were located in the United States, across IT services, business advisory, and consumer goods sectors. The attackers combined executive impersonation, vendor branding, lookalike infrastructure, and AI-assisted email generation to trick accounts payable departments into authorizing Automated Clearing House (ACH) payments of almost $50,000 per attempt.
The attack chain relied on pre-registered infrastructure, including domains like service-nowinc[.]com and domainlify[.]net acquired on July 31 to impersonate third-party vendors and C-suite executives. Messages delivered through legitimate third-party email infrastructure had C-suite sender display names, custom signatures, and direct approval notes pointing to an embedded, highly detailed invoice for a fake ServiceNow annual subscription. To reinforce credibility, the body contained a fake forwarded email thread simulating an exchange between the victim company's CEO and ServiceNow leadership regarding invoice processing and implementation details.
“Unlike traditional invoice scams that rely on a single social engineering lure, this campaign layered executive impersonation, vendor branding, fabricated invoices, and supporting email conversations into a unified narrative intended to reduce recipient skepticism,” Microsoft’s analysis says.
“The threat actor impersonated executive team members (such as a CEO, CFO, President) of multiple targeted companies, attempting to convince accounts payable departments of the same companies to process an ACH payment of nearly $50,000. More specifically, the CEOs were impersonated in multiple places in the email such as in the sender display name, reply-to display name, and in the email signature.”
BEC scams have become increasingly difficult to identify and defend against in recent years, and the rise of generative AI and other tools to create synthetic content has only compounded the problem.
Microsoft researchers saw several signs that generative AI was used during email template engineering. Code analysis of the underlying HTML showed extensive section comments, structured element labeling, highly uniform layout syntax across distinct target organizations, and distinctive formatting artifacts such as em dashes and repeated ASCII banner lines. Despite the visual complexity of the rendered lure, the underlying invoice layout was static while target organization metadata was programmatically swapped.
The Microsoft analysis showed key anomalies that identified the fraudulent nature of the messages. Most notably, the "forwarded" conversation blocks lacked standard MIME transit headers found in genuine email forwards, and nested thread responses were left-aligned rather than visually indented. Furthermore, logical contradictions were present in the lure text, such as signature instructions advising recipients not to CC the sender directly contradicting the main thread's message history.
“Microsoft observed the use of multiple financial institutions across samples, indicating that payment destinations may vary between targets. Certain parts of the invoice are personalized to the recipient. Specifically, the “BILLED TO” section has the recipient company name and executive name,” the company’s analysis says.
Dennis Fisher is an award-winning journalist and author. He is one of the co-founders of Decipher and Threatpost and has been writing about cybersecurity since 2000. Dennis enjoys finding the stories behind the headlines and digging into the motivations and thinking of both defenders and attackers. He is the author of 2.5 novels and once met Shaq. Contact: dennis at decipher.sc.