AI Is Making CEO Email Scams Harder to Spot | Sync Up

268

Microsoft says attackers sent more than a million emails impersonating company leaders and asking businesses to pay fake invoices worth nearly $50,000. Today, we’re looking at how attackers made those requests appear legitimate and where AI may have played a role, as we sit down and sync up with Rocket IT’s weekly technology update.

In this episode, you’ll hear more about:

  • How attackers impersonated company leaders to push fake payment requests.
  • How AI helped make the emails, invoices, and supporting details more convincing.
  • What warning signs Microsoft found in the fraudulent messages
  • Why businesses need both email protections and payment verification processes

Video Transcript

On September 10, Microsoft Security Research published details about a large financial fraud campaign it observed earlier this summer. Between August 3 and 5, attackers sent more than one million emails targeting businesses, with nearly 88 percent of those messages aimed at users in the United States.

The goal was straightforward. Impersonate someone like a CEO, CFO, or company president and convince the accounts payable team that an invoice had already been approved and needed to be paid.

In the examples Microsoft analyzed, the requested ACH payment was close to $50,000. But what made this campaign stand out was how much effort went into making that request appear legitimate.

The email didn’t just claim to come from an executive. Attackers included what appeared to be a professional ServiceNow invoice, complete with branding, payment information, invoice numbers, dates, and details personalized to the company being targeted.

Below that was what looked like an earlier email conversation between the company’s executive and the president of ServiceNow discussing the purchase and how the invoice should be handled. None of it was real.

Microsoft says there was no evidence that ServiceNow or the other legitimate organizations referenced in these emails were compromised. Instead, the attackers created lookalike domains, fabricated the invoices, and built fake conversations around them.

Invoice fraud and executive impersonation aren’t new. Businesses have dealt with fake payment requests for years. What’s changing is how easily attackers can create polished material that makes those requests harder to question at first glance. That’s where AI may have played a role.

Microsoft found several signs consistent with AI-assisted template development, including highly structured templates, extensive comments in the underlying HTML, and content that stayed consistent while details were changed for different companies.

That doesn’t mean Microsoft can prove exactly how much of each email was generated by AI. But what the campaign does show is how AI can make an existing scam easier to polish, personalize, and repeat across a much larger number of targets. And that matters because a lot of traditional phishing advice focuses on spotting things that look obviously wrong.

We’ve all heard about watching for spelling mistakes, awkward wording, or emails that simply don’t look professional. Those clues can still matter, but they can’t be the entire defense when a fake request includes professional branding, a convincing invoice, and what appears to be an existing conversation between company leaders.

There were still warning signs in this campaign. Microsoft found mismatches between display names and actual sender addresses, suspicious reply-to information, lookalike domains, and fake forwarded conversations that didn’t contain the normal information you’d expect from a real email thread. But someone moving quickly through a busy workday may never examine those details, especially when the message appears to have already been reviewed and approved by an executive. That’s why businesses shouldn’t rely on one employee recognizing that something feels off.

Email protections can help stop these messages before they reach someone in the first place. Microsoft recommends properly configured email authentication, spoof protection, filtering, and tools capable of identifying or removing malicious messages. But the payment process matters too.

If a request involves a large or unexpected payment, new banking information, or a change to where money is normally sent, employees should have a clear way to verify it outside of that email conversation. That might mean confirming the request with the executive through a known phone number or Teams message, requiring another person to approve larger transfers, or establishing rules around changes to vendor payment information.

For businesses, the answer isn’t asking employees to become experts at spotting AI-generated emails. It’s making sure the technology and the process work together so one convincing message can’t turn into a $50,000 mistake. If you’re wondering how well your current email protections and payment processes would hold up against a scam like this, reach out to Rocket IT using the link in this video’s description. And to stay up to date on trending technology news, hit that subscribe button and the bell to catch us on next week’s episode of Sync Up with Rocket IT.

Related Posts

Subscribe to Rocket IT's Newsletter

Stay up to date on trending technology news and important updates.

CTA2

Find out if Rocket IT is the right partner for your team

Claim a free consultation with a technology expert.

Fed up with IT support that falls short?

Claim a free 30-minute consultation and explore three key practices to evaluate the maturity of your help desk.