BlackTree Security · Infrastructure · Automation · AI

A Million Fake CEO Emails Tried to Make Finance Pay a ServiceNow Invoice That Wasn’t Real

The email appeared to come from the boss. Underneath it sat a detailed fake ServiceNow invoice. A forwarded conversation suggested that the boss had already approved the purchase. None of it was genuine. Microsoft says an attacker sent more than a million messages in just three days. The attacker wanted accounts-payable teams to transfer nearly $50,000 to its bank accounts.

The campaign did not require a breach of the company it impersonated. Microsoft’s 10 September analysis found no evidence that ServiceNow or other named organisations were compromised or involved. The attacker created lookalike domains and forged branding. It borrowed executive names and placed a fraudulent payment request inside a plausible business narrative.

That differs from the TeamSystem accounting-data breach. There, stolen transaction context could make later impersonation more convincing. Here, Microsoft describes fabricated context, not evidence of a compromised supplier.

The fake ServiceNow invoice came with its own approval

Microsoft detected the wave between 3 and 5 August. The sender display name, reply-to name and signature impersonated leaders at the recipient’s company. Those leaders included CEOs and finance executives. The message approved the invoice below it. It then showed a fabricated “ServiceNow Platform” subscription invoice with dates, line items and bank-transfer instructions. A supposed exchange between the two executives made the purchase look settled.

The requested transfer was almost $50,000, but Microsoft describes an attempted fraud, not a confirmed payment or loss. Payment destinations varied across the samples it reviewed. Most detected messages targeted users in the United States, although the campaign used multiple third-party email delivery accounts and did not depend on one victim organisation.

The supporting details made a separate confirmation feel redundant. That is the social-engineering move: make a new payment request appear approved by people the recipient knows. A convincing invoice does not prove that a supplier issued it. A forwarded-looking email thread does not verify the conversation.

What the AI evidence actually shows

Microsoft found signs consistent with generative AI assistance in the email templates. These included extensive HTML comments and unusually uniform structure. Microsoft says those signs do not establish how much content AI generated. The scale and construction of the fraud attempt are clear. AI’s exact role remains an inference from the artefacts.

That uncertainty does not weaken the practical lesson. Whether a person or a model wrote the first template, the attacker could repeat and personalise it at scale. AI may make polished lures cheaper, but the payment still depends on a human process accepting apparent authority without independent verification.

Where the story started to fray

Microsoft found clues that the thread was assembled rather than forwarded. Prior messages lacked ordinary forwarding headers. Display names did not match sender addresses, while some wording and layout were inconsistent. The attacker registered a ServiceNow lookalike domain shortly before the campaign. It was not the supplier’s real domain. These clues help analysts investigate a sample, but they should not be the only control. The next fraud may copy a real email layout more accurately.

For finance and security teams, the durable rule is to verify an unusual payment request outside the email thread, using a telephone number or contact route already on record. Treat a new bank destination, a near-deadline invoice and an executive’s apparent approval as reasons for a second check, not as reasons to skip one. Keep dual approval for material transfers even when the message appears to come from a senior leader.

On the technical side, protect and monitor executive identity domains. Enforce SPF, DKIM and DMARC where applicable. Inspect lookalike sender and reply-to domains. Use email controls that can remove malicious messages after delivery. Microsoft lists several of these measures in its report. None replaces a payment workflow that verifies who requested the transfer and where the money will go.

The attacker did not need ServiceNow’s systems or a real CEO’s mailbox to tell a convincing story. It needed a million chances for someone to believe that the hard decision had already been made.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *