In a significant cybersecurity development, Microsoft researchers have identified a phishing campaign that utilizes AI to enhance its effectiveness. This campaign has sent over a million emails aiming to execute payment diversion fraud on a large scale. The attackers impersonate key executive figures such as CEOs and CFOs of various companies. Their goal is to deceive accounts payable departments into authorizing substantial Automated Clearing House payments, often around $50,000.
The emails are crafted to appear authentic, with impersonated executive names appearing in multiple parts of the email, including the sender display name and the email signature. They contain simple directives to approve invoices and prompt users to request PDF versions if needed. The use of AI enables the attackers to generate invoices that appear legitimate and are tailored specifically for the targeted organization.
To enhance credibility, the phishing emails also include fabricated content that mimics professional invoices, such as a 'ServiceNow Platform — Annual Subscription' invoice. These invoices are detailed, featuring ServiceNow branding, invoice numbers, and payment details. They instruct recipients to transfer funds to accounts controlled by the attackers. Microsoft has noted that these accounts vary, suggesting a sophisticated operation with multiple financial institutions involved.
This campaign is notable not solely for its use of AI but for how it combines executive impersonation, vendor branding, and fabricated invoices into a seamless narrative. This strategic layering aims to minimize skepticism among recipients, making it a particularly formidable threat.

