<p>Microsoft has uncovered an industrial-scale business email compromise campaign designed to make fraudulent payment requests look like routine executive approvals. Detected between August 3 and August 5, the operation distributed more than one million messages, with nearly 88 percent directed at recipients in the United States.</p><h2>A More Convincing Financial Narrative</h2><p>The attackers impersonated senior leaders such as chief executives, chief financial officers and company presidents. Rather than sending a basic request for money, they constructed a complete business narrative around each payment. Messages included a supposed executive approval, a professionally formatted invoice carrying ServiceNow branding and a fabricated email discussion about the purchase.</p><p>The requested ACH transfers were typically close to $50,000 and directed to attacker-controlled bank accounts. Microsoft found no evidence that ServiceNow or the other legitimate organizations referenced in the messages had been compromised. The campaign instead relied on lookalike domains, manipulated sender information and third-party email delivery accounts.</p><h2>Where Artificial Intelligence Enters the Picture</h2><p>Microsoft identified several signs consistent with AI-assisted template development, including unusually descriptive HTML comments, uniform section labels and highly structured code. The evidence does not prove that an AI system generated every message, but it indicates that generative tools may have helped the attackers produce and customize professional-looking templates at scale.</p><p>In my view, this is the important development. AI does not need to invent a new attack technique to increase cyber risk. Its immediate value to criminals is operational efficiency. A fraud group can create cleaner language, convincing invoices and personalized narratives without maintaining a large team of writers and designers.</p><h3>Recommended Defenses</h3><ul><li>Require independent confirmation for new bank accounts and unexpected payment instructions.</li><li>Use a known telephone number or internal messaging channel to verify executive approvals.</li><li>Configure SPF, DKIM and DMARC protections and review third-party mail connectors.</li><li>Alert on display-name mismatches, newly registered lookalike domains and unusual reply-to addresses.</li><li>Train finance employees to inspect the structure of forwarded conversations, not just their wording.</li></ul><p>Email filtering remains valuable, but payment governance is the decisive control. Organizations should assume that future fraudulent messages will be grammatically correct, well branded and tailored to their internal processes. A mandatory out-of-band verification step can stop the transfer even when every technical and visual element of the email appears legitimate.</p>