Microsoft invoice scam emails tracked by the company combined a spoofed executive, a fake ServiceNow invoice and an invented email history in a campaign that targeted enterprise accounts-payable teams. Microsoft said it detected more than one million of the financial-fraud messages between August 3 and 5, with 87.7% sent to users in the United States.
The goal was direct: an attacker posing as an executive at a targeted company asked that company’s accounts-payable staff to initiate an Automated Clearing House payment of nearly $50,000, according to Microsoft. The company described the activity as an invoice-fraud campaign using executive impersonation, rather than a software exploit.
How did the Microsoft invoice scam emails work?
The messages built a staged business transaction around the requested payment. Microsoft said the actor used several third-party email-service accounts and attacker-controlled impersonation or lookalike domains to deliver the emails.
In the messages, the attacker spoofed company executives in the sender display name, reply-to display name and signature. The email then gave a short approval for an invoice and told recipients they could request a PDF version. Beneath that came a detailed, fraudulent invoice bearing ServiceNow branding, followed by what appeared to be forwarded correspondence between the fake executive and a spoofed ServiceNow president.
The invoice included dates, line items, a payment method and a billed-to section personalized with the recipient company’s and executive’s names. Its bank-transfer instructions pointed to accounts controlled by the attacker, Microsoft said. Microsoft observed different financial institutions in the samples, suggesting payment destinations varied by target.
The point of the assembly was to lower skepticism by putting executive identity, a familiar vendor brand, an invoice and purported supporting correspondence in one message. Microsoft said that differs from invoice scams that use one social-engineering lure.
ServiceNow and the other organizations named in the emails were targets of impersonation, not participants in the fraud. Microsoft said it found no evidence that the legitimate organizations referenced, including ServiceNow, had been compromised or involved.
What signs did Microsoft identify in the fake emails?
- The supposed forwarded messages lacked the normal data headers expected in actual forwarded email.
- Some display names did not match the sender addresses.
- Microsoft identified suspicious wording in the invented thread and financial-lure terms in subject lines.
- The invoice and conversation were fabricated, even where they used detailed branding and recipient-specific names.
Microsoft also found extensive HTML comments, structured section labels and unusually uniform template construction, which it said were consistent with AI-assisted template development. That is evidence of a possible production method, not proof that a generative AI system wrote the messages: Microsoft said it could not independently establish the extent of AI-generated campaign content.
Executive impersonation and invoice fraud predate current generative-AI tools. Microsoft’s stated concern is that AI can help attackers improve reusable templates and tailor messages, while the campaign’s multiple fabricated elements make a familiar payment request harder to assess at a glance. The supplied reporting does not identify the perpetrators or any confirmed payment resulting from the campaign.
This story draws on original reporting from The Record.