Cyber Threat Intel 6 min read

A Million Fake CEO Emails in Three Days, Written by a Model

Microsoft says the operators used generative AI to tailor each one and filled the signatures with real executive names. The pretext was a ServiceNow renewal.

Kenji Tanaka
Developer Tools & Cloud Analyst
Published 13 Sep 2026, 11:21 PM (SGT)
Share:
A stapler and pen resting on a stack of printed invoices and forms A stapler and pen resting on a stack of printed invoices and forms Photo by cloudhoreca on Pixabay
Advertisement

13 SEP 2026 — Microsoft has disclosed a campaign that sent more than a million emails over three days in August, each impersonating the recipient company's own chief executive and asking accounts payable to pay a ServiceNow subscription by bank transfer. The operators used generative AI to write them, and filled the signatures with the real names of each target's executives.

The mechanics, which are ordinary

Between 3 and 5 August the operators sent over a million messages. Each asked an accounts payable department to initiate an ACH transfer of nearly 50,000 dollars for what was presented as an annual ServiceNow subscription.

The message did not arrive bare. It carried a forwarded email thread between the impersonated chief executive and ServiceNow (itself impersonated) and a fabricated invoice. The request reached the clerk as the last step of a conversation that appeared to have already happened.

Nothing in that is novel. Invoice fraud is among the oldest frauds in commerce and the software-subscription variant has been running for years. What has changed is the ability to personalise these attacks at scale.

Targets were United States enterprises across IT services, consumer goods, real estate and discrete manufacturing. The operators identified chief executives, chief financial officers and presidents at each one, then put those names and addresses into the signature block. Generative AI produced the templates and tailored the drafts to each recipient.

1m+Emails, across three days
3-5 AugThe window
ACHThe payment rail requested
~$50,000The sum requested, against a fabricated invoice

What the AI actually bought them

Most coverage says "AI-powered phishing" without explaining what the AI actually did.

Personalised fraud has always worked better than generic fraud and has always cost more per target, because somebody had to research the company and write the message. That research-and-write step is what a language model now performs, which collapses the cost of tailoring toward the cost of sending.

The measurable consequence is a million tailored emails in three days. It is not a cleverer fraud. It is the same fraud, at a volume that previously required it to be generic, now carrying the executive names that make a finance clerk hesitate.

Advice built on spotting bad English, wrong logos or generic greetings was always weak. It is now close to useless, because those were artefacts of the cost constraint that has just been removed.

Why ServiceNow, and why ACH

Both choices are deliberate and both are about plausibility rather than technology.

An enterprise software subscription is a large, annual, unremarkable payment that a finance team expects to see and cannot easily verify from the invoice alone. Renewals arrive once a year, often from a reseller, and the person paying rarely owns the contract. A fake invoice for enterprise software looks much like a real one.

ACH is the American bank transfer rail. It is cheap, fast within a day, and difficult to reverse once settled. The fraud does not need to survive scrutiny for long. It needs to clear before anyone asks the chief executive whether they actually sent that.

The control that works is procedural

No email filter reliably catches this, and it is more useful to say so than to pretend otherwise. A well-written message from a plausible sender about a real vendor, with correct executive names, has few of the signals a filter scores on.

What does work is a rule about the payment rather than the message. Any change to bank details, and any first payment to a new account, is verified by a call to a number already on file — not a number in the email. That control is decades old, costs nothing, and fails only when somebody is in a hurry.

Advertisement

A second control, especially for smaller firms, is separation of duties: the person who receives an invoice should not be the one who can pay it. Separation of duties is the thing that turns a convincing email into a conversation.

Why this travels beyond the US

The targets here were American and the rail was ACH, so the direct exposure is limited.

The transferable part is the method. The same model that writes a convincing ACH request writes a convincing GIRO or FAST instruction, and the executive names are as public in Singapore or Kuala Lumpur as they are in Ohio. Nothing about the technique is tied to the jurisdiction; only the payment rail and the language change, and neither is a barrier.

Worth noting alongside that: invoice fraud of this kind sits beside the industrialised regional fraud economy we have tracked in Southeast Asia's scam economy, but it is a different business. This is a low-headcount operation with a language model, not a compound with staff.

What to watch

Whether anyone publishes a success rate. A million emails is an input measure, and the number that would tell us whether AI-written fraud converts better than the handwritten kind is the one nobody releases.

And whether the pretext rotates. ServiceNow was chosen for plausibility rather than for any property of ServiceNow, so the same campaign with a different vendor name is the cheapest possible variation.

Advertisement
Kenji Tanaka
Developer Tools & Cloud Analyst

Kenji Tanaka covers developer tools, cloud platforms, DevOps, CI/CD, and software supply-chain topics for RECATOOLS.

View author profile → · Editorial policy

About this byline Kenji Tanaka is a RECATOOLS editorial persona for developer tools, cloud, DevOps, and software supply-chain coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Corrections policy

Advertisement