What Microsoft’s Million-Email Campaign Reveals About Invoice Fraud in the AI Era

Key takeaways
- Microsoft detected more than 1 million phishing emails between August 3 and 5, 2026, with 87.7% targeting U.S. users; Microsoft cited technical signals like templated formatting, unusually uniform structure, and explanatory code comments as signs of generative AI involvement, while cautioning that the exact degree of AI use is unproven.
- The campaign impersonated CEOs and used a fake forwarded thread with a supposed ServiceNow executive, a lookalike domain registered days earlier, and an attached invoice styled as a ServiceNow subscription renewal to trick accounts payable staff into sending an ACH transfer of nearly $50,000; Microsoft said ServiceNow was not compromised.
- Microsoft 365 defenses blocked part of the campaign, including post-delivery removal via Zero-hour Auto Purge, underscoring that automated filtering helps but still leaves a gap that process-based verification must close.
- University at Buffalo professor Arun Vishwanath’s research says information-rich phishing creates a sense of 'social presence' that reduces distrust and encourages less careful, heuristic decision-making; he also wrote in Harvard Business Review that generative AI is making phishing more advanced, harder to spot, and more dangerous.
- Cambridge researchers Frank Stajano and Paul Wilson argue scams exploit the 'Social Compliance Principle'—people’s tendency not to question authority—and that urgency pushes victims toward less careful reasoning, which helps explain why polished executive-impersonation invoice fraud works on capable employees.
- The article’s main countermeasures are to verify new or changed bank details through a trusted second channel, require a second approver above a set dollar threshold, be extra cautious with familiar vendor names like ServiceNow, and rehearse realistic invoice-fraud scenarios so teams build a repeatable 'pause, verify, then act' habit.
Inside the Campaign
Between August 3 and 5, 2026, Microsoft detected a campaign of more than one million phishing emails, with 87.7 percent sent to users in the United States. Microsoft disclosed the details this month, along with a set of technical signals, extensive templated formatting, unusually uniform structure, and explanatory code comments typical of AI-generated content, that point toward generative AI assembling the campaign at scale. Microsoft was careful to note those signals suggest AI involvement without establishing exactly how much of the campaign AI produced, and that caution is worth keeping in mind before drawing bigger conclusions than the evidence supports.
The emails impersonated company CEOs and built the illusion of legitimacy around a fabricated forwarded thread, styled to look like an ongoing conversation between that CEO and an executive at ServiceNow, a vendor most finance teams already recognize. The attached invoice was titled to match a ServiceNow subscription renewal, and the sender used a lookalike domain registered days before the campaign began. Microsoft confirmed ServiceNow itself was never compromised or involved. The target was accounts payable staff, asked to process an ACH transfer of nearly fifty thousand dollars to an account the attacker controlled.
Microsoft's own filters flagged a portion of this traffic as spam or malicious and removed some of it after delivery through Zero-hour Auto Purge, a Microsoft 365 feature that keeps rechecking mail after it lands and pulls anything later flagged as malicious back out of inboxes. That detail matters more than it might seem to. Automated defenses caught meaningful ground here, after messages had already reached mailboxes, which is exactly the gap a verification habit is built to close.
Why the Craftsmanship Mattered
The scam itself is a familiar one. Fake invoices and impersonated executives have worked on finance teams for years. The craftsmanship is what changed here, and that shift is worth studying closely, because it shows exactly where the old defenses still hold and where they need reinforcement.
Arun Vishwanath, a professor at the University at Buffalo who has spent years studying why phishing succeeds, has found that emails rich with specific, personal-sounding detail create what he calls a feeling of social presence, the sense of corresponding with an actual person. “Presence makes a message feel more personal, reduces distrust, and also provokes heuristic processing, marked by less care in evaluating and responding to it,” his research on information-rich phishing lures concluded. Writing in Harvard Business Review with his coauthors, Vishwanath put the AI shift plainly: generative AI tools are making these emails more advanced, harder to spot, and significantly more dangerous. This campaign reads like an illustration of that shift, regardless of how much of it Microsoft can attribute to AI with certainty.
A request can carry the right vendor name, the right tone, and an invoice format matching every one a company has paid before, and still be fraudulent. The fix was never about catching a typo or an odd turn of phrase. A verification habit built around checking a request through a second channel works the same way against a polished forgery as it does against a clumsy one.
Frank Stajano, a professor of security and privacy at the University of Cambridge, and his coauthor Paul Wilson have studied why capable people fall for scams built this way. “Society trains people to not question authority,” they wrote of what they call the Social Compliance Principle, the psychological foundation impersonation scams like this one are built on. Urgency compounds it. “When under time pressure to make an important choice, we use a different decision strategy,” one that leans on less careful reasoning, they found. Their central finding is worth sitting with: ordinary human decision-making, the same reflexes that make someone a responsive colleague, is what these tactics are built to exploit.
What Holds Up
A few practices hold up well against this pattern.
- Verify any new or changed bank detail through a channel the company already trusts, a callback to a number already on file rather than one supplied inside the email.
- Set a dollar threshold that requires a second approver on every transfer above it, regardless of how routine the request looks. Fifty thousand dollars sits exactly where a second signature costs little and catches a great deal.
- Treat a familiar vendor name as a reason to verify a little harder. Attackers picked ServiceNow specifically because recognition lowers a reader’s guard.
- Give the person reviewing the request permission to pause without it feeling like an accusation. A verification step only works when using it carries no social cost.
- Rehearse the specific scenario a team is likely to face, on top of the general policy. A finance team that has walked through “what if this exact email landed today” catches it faster than a team meeting the pattern for the first time in production.
This is the muscle Adaptive builds through simulation, and it applies directly here. Adaptive runs realistic email, SMS, and voice phishing simulations, including scenarios built around exactly this kind of forged invoice and impersonated executive. A finance team that has practiced this specific pattern carries the instinct into whatever channel the next version arrives through, because the skill underneath all of them is identical: pause, verify through a second channel, then act. Adaptive’s cloud email security product adds a second layer working before that habit is even called on, sitting on top of Microsoft 365 or Google Workspace to flag and quarantine BEC and wire-fraud attempts a signature-based filter would miss, with the reasoning behind each flag shown alongside it. Building both the habit and that layer of detection ahead of time does more good than teaching anyone to read polished prose for tells that keep getting harder to find.
The Pattern That Outlasts the Headlines
Every headline-grabbing campaign like this one gets its news cycle, then makes room for the next one. What it revealed sticks around much longer. Any company that trusts a vendor name, an executive’s authority, or an inbound invoice as part of normal business, which describes nearly every company that pays bills, carries the same exposure this campaign just put on display.
Asaf Cidon, a professor of electrical engineering and computer science at Columbia University who studies how cybercriminals use technology, put the fix in plain terms. “If I get a phone call from a random number next week, and my wife comes on the line and pleads with me to immediately wire her money, I'm going to insist on calling her back on a different number,” he said. That same instinct, aimed at an invoice instead of a phone call, is the entire defense this moment calls for.
There is a genuinely encouraging takeaway underneath all of it. Verification doesn’t care how good the forgery is once it’s built into how a team operates day to day. Whoever tests this specific pattern against their own approval process this month walks into the next attempt already prepared, however convincing it looks on arrival.