Mass Email Fraud Uses CEO Impersonation to Push $50K Scams

Between August 3 and August 5, hackers sent over one million fraudulent emails in a wide-reaching campaign aimed at tricking employees into wiring nearly $50,000 to criminal-controlled bank accounts. The scheme didn’t rely on malware or exploits, but on impersonation, phishing, and carefully crafted social engineering. 87.7 percent of the targets were U.S.-based staff working in accounts payable or finance roles.

How the Scam Worked

Emails mimicked senior executives—CEOs, CFOs, and presidents—by forging display names, reply-to addresses, and signatures. Each email requested approval for an invoice, with a note that a PDF version could be supplied if needed. These messages mimicked internal approvals and vendor communications so closely that many victims may not have thought twice.

Invoices bore familiar vendor branding—like ServiceNow—and included legitimate-looking details: invoice numbers, dates, itemized charges, and payment instructions. The “billed-to” area was customized with the target company’s and executive’s names. Even when multiple financial institutions were involved, the payment paths matched the specific target.

AI Template Use & Domain Tricks

While the exact role of AI remains unproven, Microsoft analyzed the messages and noted strong signs of template automation: consistent HTML structure, clean sections, lookalike domains, and use of third-party delivery setups. Fraudsters registered domains similar to trusted suppliers and used them in contact or reply-to fields to enhance credibility.

Some anomalies were present—visual cues and subject lines felt “off.” Messages often lacked normal email headers or contained odd spellings in the subject like “ACH Parment.” The alignment of forwarded sections was inconsistent, and in many cases the displayed sender name didn’t match the actual email address.

Defensive Steps Companies Should Take

To protect against this kind of fraud, finance teams should treat payment requests as processes rather than decisions. Urgent approvals, bank detail changes, or unusual invoice instructions should be verified through a known phone number or separate channel—not via email replies.

Technical safeguards also matter: configuring SPF, DKIM, and DMARC standards; enabling filtering and spoof protection; reviewing email flow; and quarantining or removing suspicious messages post-delivery. Training staff, especially in finance roles, to recognize telltale signs—such as mismatches in sender addresses or invoice anomalies—is also critical. Organizations should also set up easy paths for employees to report potentially fraudulent messages.

Listed indicators of compromise include domains like “service-nowinc[.]com,” sender addresses such as “gomez@service-nowinc[.]com” or “notifications@uinsure[.]co[.]uk,” and others tied to similarly crafted lookalike setups. Monitoring and blocking such domains or email addresses can catch related attacks.

This campaign highlights the growing sophistication of business email compromise attacks. By blending impersonation with vendor-branded collateral and AI-style template designs, attackers aim to reduce suspicion and push through costly payments.

What this means: even well-resourced organizations’ finance departments can be vulnerable when systems and culture reward speed over verification. The shift toward using realistic impersonation and AI-style tools demands that security controls, employee training, and payment policies evolve in tandem. What to watch: whether AI-assisted phishing becomes the norm, how business email compromise defenses improve, and how companies balance speed with safety in financial workflows.