Detect Deepfakesby Resemble AI
Deepfake case study · Multi-modal

Protecting organizations from AI-assisted executive…

Between August 3 and 5 2024 threat actors launched a massive campaign impersonating CEOs to trick finance departments into processing fraudulent ACH payments

Incident date
Aug 2024
Target
CEOs and executive team members of multiple enterprises
Updated Sep 11, 2026 · 1 min read

Between August 3 and 5, 2024, Microsoft detected a large-scale phishing campaign targeting over a million enterprise users. The attackers impersonated executive team members, such as CEOs and CFOs, to convince accounts payable departments to process nearly $50,000 in fraudulent Automated Clearing House (ACH) payments. The majority of these emails targeted organizations in the United States across industries including IT services, business advisory, and consumer goods.

What happened

The campaign utilized sophisticated social engineering by layering executive impersonation with fabricated vendor documentation. Threat actors registered lookalike domains, such as service-nowinc[.]com, to mimic trusted brands and individuals. The emails featured a direct approval request from a spoofed CEO, accompanied by a fabricated ServiceNow invoice that included personalized details like the recipient company’s name and executive contact information. To further increase legitimacy, the attackers included a fake "forwarded" email thread between the target company’s CEO and the president of the impersonated vendor, discussing the invoice and purchase.

Microsoft observed several indicators consistent with the use of generative AI in the development of these campaign templates. The emails contained highly uniform construction, verbose HTML comments describing sections, and structured section labeling—characteristics frequently associated with AI-generated code. Despite the professional appearance of the content, the attack contained several inconsistencies detectable by vigilant staff. For instance, the "forwarded" email threads lacked standard header data, the display names often did not match the sender addresses, and the conversation flow contained suspicious instructions, such as an executive requesting that the recipient not copy them on the email.

Throughout the operation, the threat actors relied entirely on attacker-controlled infrastructure and fraudulent content. Microsoft confirmed that legitimate organizations, including ServiceNow, were not involved in or compromised by the activity. The campaign effectively utilized these synthesized narratives to lower recipient skepticism and facilitate financial theft.

Sources