Massive BEC wave targets Microsoft users with fake executive invoices
Over a million fraudulent invoice emails were blasted at Microsoft users in early August, with attackers trying to steal almost $50,000 from accounts‑payable teams.
Microsoft’s threat‑intel team traced the campaign to a network of third‑party mailing services. The senders pretended to be senior executives and even spoofed ServiceNow’s brand, attaching a fabricated “forwarded” thread that appeared to come from a fake CEO to the SaaS vendor.
What the email looked like
Each message followed a rigid template: long HTML comments peppered throughout the source, numbered sections labeled “Step 1”, “Step 2”, and a uniform layout that made the whole batch look like it was generated from a single script.
- Extensive HTML comments hidden in the body
- Structured section labeling (e.g., “Step 1 – Review”)
- Identical header/footer blocks across messages
Microsoft flagged those patterns as “consistent with AI‑assisted template development,” but the company also noted it could not independently verify that generative AI actually produced the content. (That claim remains unconfirmed.)
Who was hit
Roughly 88 % of the recipients were based in the United States, mainly finance or procurement staff who handle vendor payments. The fake invoices asked for a single payment of about $50,000, routed to accounts controlled by the fraudsters.
Defensive steps for organisations
- Train AP and finance teams to treat any out‑of‑band request for payment as suspicious, especially when it claims to come from a CEO or a partner like ServiceNow.
- Adopt a verification workflow: confirm the request through a separate channel (phone call, chat) before wiring money.
- Enable strong email authentication (DMARC, SPF, DKIM) and monitor for anomalies in sender domains.
- Deploy anti‑phishing solutions that can detect the tell‑tale HTML comment patterns and template uniformity.
- Enforce MFA on all Office 365 accounts and limit the use of third‑party bulk‑mailing services.
Even though the campaign’s scale was unprecedented, the tactics are classic BEC – a social‑engineering play that relies on trust, not on a zero‑day exploit. Keeping verification habits sharp is the cheapest, most reliable shield.
