Microsoft sees some new wrinkles in invoice-scam emails
Security researchers at Microsoft recently spotted a flood of fraudulent emails that highlight how 2026-9-11 17:49:46 Author: therecord.media(查看原文) 阅读量:2 收藏

Security researchers at Microsoft recently spotted a flood of fraudulent emails that highlight how threat actors are increasingly using AI in attempting to bilk companies.

Business email compromise (BEC) scams have been around for a while, but the researchers said that what’s notable is how the “adoption of AI has enabled threat actors to improve their campaign templates and construct emails tailored to their recipients.”

Also new, according to Microsoft: Fraudsters are using multiple tactics in the same email to make the missives appear to be authentic. 

In early August, the researchers found a campaign made up of more than a million emails targeting its users. Using several third-party services to dispatch the emails, the attackers impersonated top executives at firms, telling accounts payable departments to send fraudulent payments of nearly $50,000. 

The attackers made the emails appear more legitimate by including a forwarded email thread from the fake CEO to ServiceNow, a cloud-based enterprise platform that automates workflows and business processes. (ServiceNow also was impersonated.)

The forwarded emails fabricated an email chain where the phony CEO sent invoices allegedly received from ServiceNow (which was also being impersonated).

About 88% of the campaign’s targets are American.

“Unlike traditional invoice scams that rely on a single social engineering lure, this campaign layered executive impersonation, vendor branding, fabricated invoices, and supporting email conversations into a unified narrative intended to reduce recipient skepticism,” the report said.

Microsoft found several indicators “consistent with AI-assisted template development. These included extensive HTML comments, structured section labeling, and highly uniform template construction,” the report said.

However, while Microsoft suggests generative AI is involved, the report said it cannot  “independently establish the extent to which AI generated campaign content.”

Attackers are using AI to make established fraud schemes “more sophisticated and scalable, according to Nick Tausek, lead security automation architect at Swimlane, a security automation and response platform.

“Safeguards need to reflect that reality, with greater attention to how models can be used to generate deceptive content at volume,” he said in an email.

“Policymakers also need to account for how quickly useful AI capabilities can be adapted once they’re in an attacker’s hands.”

Recorded Future

No previous article

No new articles

Suzanne Smalley

Suzanne Smalley

is a reporter covering digital privacy, surveillance technologies and cybersecurity policy for The Record. She was previously a cybersecurity reporter at CyberScoop. Earlier in her career Suzanne covered the Boston Police Department for the Boston Globe and two presidential campaign cycles for Newsweek. She lives in Washington with her husband and three children.


文章来源: https://therecord.media/invoice-scam-emails-new-features-microsoft-researchers
如有侵权请联系:admin#unsafe.sh