Microsoft described a campaign using generative AI to scale executive impersonation and invoice fraud. Attackers targeted accounts-payable employees with requests to authorize large ACH payments.

Microsoft reported a campaign involving more than one million emails connected to financial fraud. The attackers allegedly used AI-assisted techniques to impersonate business executives and pressure accounts-payable personnel into approving unauthorized payments. In some cases, the requested ACH transfers approached $50,000. The campaign illustrates how criminals can use generative AI to produce convincing messages at much greater scale, while maintaining familiar business-email-compromise tactics such as urgency, confidentiality, and authority. Organizations should treat payment instructions received by email as untrusted until independently verified. Verification should use a known telephone number or a separate communication channel rather than replying to the original message. Companies can also reduce risk through multifactor authentication, payment approval controls, domain monitoring, employee training, and alerts for unusual vendor or bank-account changes.