Microsoft security researchers have detected a new trend in business email compromise (BEC) invoice scams, noting that threat actors are increasingly using AI to refine their fraudulent email campaigns. This development allows attackers to create more tailored and convincing messages, moving beyond traditional single-lure social engineering tactics.
The new scams incorporate multiple deceptive elements within a single email to enhance authenticity. Attackers are combining executive impersonation, vendor branding, fabricated invoices, and supporting email conversations into a unified narrative. For example, some emails included a forwarded thread from a fake CEO to ServiceNow, impersonating both the executive and the cloud platform.
In early August, Microsoft identified a campaign comprising over one million emails targeting its users. These attacks impersonated top executives and instructed accounts payable departments to make fraudulent payments of nearly $50,000. The majority of the campaign's targets, approximately 88%, were located in the United States.
Microsoft found several indicators consistent with AI-assisted template development in the fraudulent emails. These included extensive HTML comments, structured section labeling, and highly uniform template construction. While Microsoft suggests generative AI is involved, the report notes it cannot independently establish the full extent of AI's role in content generation.
The use of AI makes established fraud schemes more sophisticated and scalable, according to Nick Tausek, lead security automation architect at Swimlane. This necessitates updated safeguards, with increased attention to how AI models can generate deceptive content at volume. Policymakers also need to consider the rapid adaptation of useful AI capabilities for malicious purposes.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Microsoft security researchers identified a new wave of business email compromise (BEC) invoice scams using AI to create more convincing and tailored fraudulent emails. Attackers are combining executive impersonation, vendor branding, and fabricated email chains to increase legitimacy, with a campaign in early August targeting over a million users, primarily in the US.