Cybersecurity

Microsoft Detects Financial Fraud Campaign Impersonating Executives and Requesting ACH Transfers

Microsoft detected a campaign involving more than one million emails impersonating CEOs and ServiceNow to persuade accounts payable teams to transfer approximately $50,000 via ACH. The company says the campaign used third-party sending infrastructure and content showing indicators of development with AI assistance, with no evidence that the impersonated organizations were compromised.

2026-09-10
4 min read
9 views
فريق تحرير certi.news
Microsoft Detects Financial Fraud Campaign Impersonating Executives and Requesting ACH Transfers

Microsoft disclosed a financial fraud campaign involving more than one million emails that targeted users at organizations and attempted to persuade accounts payable teams to execute Automated Clearing House (ACH) transfers of approximately $50,000. The activity was observed between August 3 and 5, and 87.7% of the messages were directed at users in the United States.

The campaign relied on impersonating CEOs, CFOs, and company presidents at the targeted organizations. The names of the impersonated officials appeared in the sender name, reply name, and signature, while the messages requested approval of the “invoice” or asked recipients to send a PDF copy of it. To enhance credibility, the message included an alleged conversation between the targeted company’s CEO and the president of ServiceNow, along with a fake invoice for “ServiceNow Platform — Annual Subscription.”

Multilayered Fraud Infrastructure

The invoice included its number, issue and due dates, currency, amount, and detailed line items, while directing the recipient to transfer funds to accounts controlled by the attackers. Some details, such as the recipient company’s name and the CEO’s name, were also customized. Microsoft noted the use of multiple financial institutions in the samples, meaning that the payment destinations were not consistent across all targets.

The attackers registered lookalike domains before launching the campaign, including service-nowinc[.]com, which was used to impersonate the ServiceNow president’s address and in the invoice details, as well as domainlify[.]net, which was used in the Reply-To field. Microsoft confirmed that there was no evidence of a compromise of ServiceNow or the other organizations mentioned, as the activity relied on domains and content created by the attackers to imitate trusted entities.

Indicators of AI Use

Microsoft observed numerous HTML comments, organized section labels, and a consistent template structure, along with consistent invoice identifiers and narrative sequencing despite changes to the targeted organizations’ data. The company said that the use of em dashes and decorative separators could also be consistent with templates created with AI assistance. However, it stressed that these indicators alone do not establish the extent of the content created with AI or its role in the campaign.

The messages still contained signs that defenders could detect, including a mismatch between the display name and the sender address, suspicious financial phrases such as “ACH Parment,” and the absence of the usual header data in forwarded messages. Previous email threads were also not displayed in the customary visual format, and there were inconsistencies in the instructions for sending the invoice and copying recipients.

What Matters to Security and Finance Teams?

The campaign demonstrates that invoice fraud does not necessarily depend on a single financial request; the attackers combined executive impersonation, a well-known vendor brand, a detailed invoice, and a supporting conversation into a single narrative targeting payment procedures and the employee’s trust in the context surrounding the request. Therefore, checking the sender address alone is insufficient. Transfer requests should be verified through an independent channel, especially when the message asks that the requester not be copied or requests a change in the payment method.

Microsoft recommends enabling the SPF, DKIM, and DMARC email authentication mechanisms, configuring impersonation protection and mail-flow rules, and using anti-phishing solutions. It also suggests enabling Zero-hour Auto Purge to quarantine malicious messages detected after delivery, and using Microsoft Defender XDR and Security Copilot for investigation and response. These measures remain recommendations from Microsoft tied to its products; behavioral indicators, such as independently verifying the bank account and the request, remain important operational controls even in environments that use different security tools.

News source
Microsoft Security Blog
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news