Artificial intelligence has significantly amplified the capabilities of cybercriminals, allowing them to conduct phishing campaigns on an unprecedented scale. Recently, Microsoft researchers uncovered a phishing operation where an unidentified threat actor sent over one million personalized emails within a span of three days. These emails were strategically targeted at accounts payable departments and cleverly personalized using AI, incorporating real executive names and creating convincing interactions.
The fraudulent emails claimed that the recipient's company owed nearly $50,000 to ServiceNow for an annual subscription. Each email included a detailed invoice with realistic elements, making the scam appear legitimate. To further enhance credibility, the attackers fabricated an email thread that seemed to be a prior conversation between an executive at the victim's company and a ServiceNow representative, thereby increasing the likelihood of the recipient falling for the scam.
The campaign targeted a wide range of industries, particularly IT, consumer goods, and real estate, with the majority of targets based in the United States. This operation highlights how AI can streamline the gathering of publicly available information to create highly personalized and convincing phishing emails.
Experts emphasize that AI is enhancing traditional cyber threats rather than creating entirely new ones. The ability to rapidly generate personalized phishing emails demonstrates the increasing sophistication and scale of cyberattacks. Despite the technological advancements, fundamental cybersecurity practices remain crucial. Organizations are advised to maintain strong email security measures and continue educating employees on recognizing phishing attempts.

