Microsoft’s latest threat intelligence report is a useful warning for any organization that still treats invoice approval as a mostly human trust exercise. The campaign Microsoft observed used third-party email delivery infrastructure, executive impersonation, lookalike domains, fabricated vendor invoices, and staged “forwarded” email threads to pressure accounts payable teams into ACH transfers near $50,000.

The important part is not that business email compromise is new. It is not. The shift is that generative AI makes the lure easier to scale and easier to personalize. Attackers can now build polished invoice templates, consistent executive narratives, and realistic-looking internal conversation threads fast enough to target many companies at once.

What Microsoft reported

According to Microsoft Security, the campaign sent more than one million financial-fraud emails between August 3 and August 5, with most targeting users in the United States. The messages impersonated executives such as CEOs, CFOs, and presidents, then paired the executive approval request with a fake ServiceNow-themed invoice and supporting email conversation.

Microsoft noted that the legitimate brands referenced in the lures were not compromised. The actor relied on attacker-controlled infrastructure, including lookalike domains, reply-to manipulation, and fraudulent invoice content designed to mimic trusted vendors and internal leadership.

Why this matters for SMBs and government contractors

Smaller organizations often have thinner separation between executives, finance staff, IT, and vendor management. That makes a convincing “please process this today” request dangerous, especially when it appears to come from a known leader and references familiar SaaS or professional services vendors.

For government contractors, the risk is not only the direct payment loss. A successful BEC incident can expose banking data, vendor relationships, internal approval patterns, and employee inbox content. Those details can feed later phishing, subcontractor targeting, or supplier impersonation.

Defensive takeaways

  • Require out-of-band verification for payment changes. New ACH instructions, urgent invoices, and vendor bank changes should require confirmation through a known phone number or approved vendor portal — not a reply to the email thread.
  • Separate approval from execution. The same person should not be able to approve and initiate a high-risk payment without secondary review.
  • Tune detections for display-name and reply-to abuse. Finance-facing mailboxes need extra scrutiny for executive names that do not align with authenticated sender domains.
  • Audit third-party mail-flow connectors. If email security tools sit behind external delivery services, make sure SPF, DKIM, DMARC, enhanced filtering, and connector trust are configured correctly.
  • Train on forged thread structure, not just bad grammar. AI-generated lures may read well. Staff should look for mismatched headers, unusual forwarding layout, rushed payment language, and vendor details that cannot be validated independently.
  • Use post-delivery remediation. If one message is confirmed malicious, security teams need a process to search, quarantine, and remove matching messages already delivered to other inboxes.

Bulwark Black assessment

This is where AI changes the economics of fraud. It does not need to invent a new attack class to matter. It makes an old attack cleaner, faster, and more convincing at scale. The right response is not panic over every polished email; it is designing finance workflows so that email alone cannot authorize money movement.

If your organization relies on inbox trust for invoices, payment changes, subcontractor billing, or executive approvals, treat that as an exposed business process. Map the workflow, define the verification step, and make the control mandatory before the next urgent invoice lands.

Original source: Microsoft Security — Protecting organizations from AI-assisted executive impersonation and invoice fraud