Microsoft describes more than one million emails using fake executives, invoices, and vendor branding to request payments. Finance teams should verify unusual requests outside email before sending money.
In 60 seconds
- Enterprise finance and accounts-payable teams should care about payment requests that appear to come from company leaders.
- Check the full sender address, reply address, invoice, and expected purchase before approving payment.
- Pause unusual requests and verify them through a known phone number or separate conversation.
- Do not trust a leader’s name, company logo, forwarded thread, or message contact details alone.
Who should care and what to do first
Enterprise finance and accounts-payable teams should pay attention to payment requests that appear to come from company leaders. Microsoft says it detected more than one million emails sent between August 3 and 5 to enterprise users. The messages asked staff to send nearly $50,000 through an automated bank-to-bank payment, known as an ACH payment.
To tell whether this situation may affect your organization, review unusual payment requests for a new sender address, a different reply address, an unexpected invoice, or instructions that do not match your normal approval process. Microsoft described this campaign as targeting enterprise users. Other organizations that approve bills can use the same checks for similar scams, but the source does not identify them as targets of this campaign.
If a request seems unusual, pause the payment today. Contact the executive or vendor through a phone number, email address, or other contact method already in your records. Do not use the contact information in the suspicious message or invoice. Do not reply until the request has been checked.
How the messages were made to look real
The emails appeared to come from executives, including chief executive officers and chief financial officers. They included a fabricated vendor invoice and a made-up conversation between the supposed executive and ServiceNow. The invoice instructed recipients to send a bank transfer to an account controlled by the sender.
Microsoft found no evidence that ServiceNow or the other legitimate organizations named in the messages were compromised or involved. The campaign used attacker-controlled domains, fake communications, and outside email delivery services.
Microsoft observed attacker-controlled or lookalike domains in the messages, including a newly registered domain used in the reply address. A familiar name in the inbox does not prove that the message came from that person. Check the full email address, not just the name shown beside it.
Checks before money moves
Review the full sender address and the address used for replies. Look for a lookalike domain, a request to skip normal approval, pressure to act quickly, or instructions not to copy someone who normally handles the payment.
Compare the invoice with an expected purchase and with the vendor information already in your records. A detailed invoice, familiar logo, or forwarded thread can still be fabricated. Microsoft noted that some supposed forwarded messages lacked normal headers and did not look like ordinary grouped email threads.
Use the organization’s usual approval process, even when the request appears to come from a senior leader. A second person should review the request, invoice, and payment destination before funds are sent. Preserve suspicious messages and send them to the person or team that handles suspicious email.
What Microsoft said about artificial intelligence
Microsoft observed signs consistent with artificial intelligence helping create the email templates. The signs included detailed code comments, repeated layouts, and similar invoice structures with recipient-specific details.
Microsoft could not determine how much artificial intelligence was used. For the person receiving the message, the practical lesson is simple: polished writing and a personalized invoice are not proof that a payment request is genuine.
Microsoft’s published enterprise guidance includes email authentication, anti-spoofing controls, and tools that can quarantine or remove malicious messages. Those are organization-level measures. They do not show that a particular reader’s mailbox received this campaign.
Does this affect me?
- Who may be affected
- Enterprise finance and accounts-payable teams should care because Microsoft reported this campaign targeting enterprise users. Any organization that approves invoices can apply the same checks to similar payment-impersonation scams, but the source does not identify schools, nonprofits, libraries, local governments, or small businesses as targets in this campaign.
- How to check
- Review unusual payment requests for mismatched display names and sender addresses, attacker-controlled or lookalike domains, a newly registered domain in the reply address, unexpected invoices, requests to bypass approval, or payment instructions that do not match vendor records.
- What to do
- Pause the payment and verify the request through a known phone number or separate contact method before sending money.
- What to avoid
- Do not rely on an executive name, logo, forwarded thread, or contact information in the suspicious message as proof of approval. Do not reply to the sender before checking the request.
Common questions
Was ServiceNow hacked in this campaign?
Microsoft found no evidence that ServiceNow or the other legitimate organizations named in the messages were compromised or involved. The invoices and communications were fabricated, and the domains used in the messages were controlled by the sender.
Does an AI-assisted email prove that it is a scam?
No. Microsoft observed signs consistent with artificial intelligence helping create the templates, but could not determine how much artificial intelligence was used. Check the sender, invoice, approval process, and payment details instead.
What should an organization do if it already sent the payment?
As general response guidance, contact the bank promptly, notify the organization’s finance or leadership contact, and preserve the email, invoice, and payment details. Do not continue the conversation with the sender.
Primary source
This article is based on Microsoft Security Research, “Protecting organizations from AI-assisted executive impersonation and invoice fraud,” published September 10, 2026: https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/. The campaign details come from Microsoft. The payment-checking advice is general guidance. Read the complete original source.
Get the important updates without the noise
Choose the devices and topics you care about in Cyber Alerts.
Article history: Published Sep 11, 2026 at 6:40 am EDT. Updates and corrections are noted here when material facts change.
