AI Is Making Business Email Scams Much More Convincing
Business email compromise, often called BEC, has been around for years.
The basic idea is simple: an attacker pretends to be someone an employee trusts—such as the CEO, CFO, vendor, accountant, or another executive—and requests money, credentials, or sensitive information.
What is changing is the quality of the deception.
Microsoft Security Research recently analyzed a financial-fraud campaign showing multiple indicators consistent with generative AI being used to build and customize fraudulent email templates. Rather than sending a simple message asking someone to transfer money, the attackers created an entire believable business story around the request.
The campaign Microsoft observed between August 3 and August 5, 2026 involved more than one million emails. Approximately 87.7% of those messages were sent to users in the United States.
The Attack Looked Like a Normal Business Transaction
The attackers impersonated executives such as CEOs, CFOs, and company presidents.
Employees responsible for accounts payable received messages appearing to show that an executive had already reviewed and approved an invoice.
But the attackers went much further.
The messages included a professional-looking fake invoice impersonating ServiceNow, complete with branding, invoice numbers, payment details, company information, and an amount approaching $50,000. They also inserted fabricated forwarded email conversations designed to look like previous discussions between company leadership and the supposed vendor.
Microsoft emphasized that it found no evidence that ServiceNow or the other legitimate organizations referenced in the emails were compromised. Attackers instead created lookalike domains, fraudulent communications, and fake documents designed to mimic trusted businesses.
That distinction matters.
The attacker does not necessarily need to hack your vendor.
Sometimes they simply need to convince your employee that they did business with them.
Why AI Changes the Phishing Problem
Employees have traditionally been taught to look for obvious phishing indicators:
Misspelled words. Strange grammar. Poor formatting. Generic greetings. Suspicious-looking documents.
Those warning signs are becoming less reliable.
Generative AI gives criminals the ability to rapidly create polished business emails, invoices, executive communications, and supporting narratives.
Microsoft's investigation found indicators suggesting AI-assisted template development, including highly structured and reusable templates that could be customized for individual organizations.
Instead of sending one generic phishing email to thousands of companies, attackers can increasingly create messages that appear tailored to:
- Your company
- Your executives
- Your accounting department
- Your vendors
- Your industry
- Your normal business processes
The result is a scam that can look much more like legitimate business communication.
Why Small and Midsize Businesses Should Pay Attention
The Microsoft campaign specifically documented targeting of enterprise users, but the techniques are extremely relevant to smaller organizations.
Small and midsize businesses often operate with smaller accounting teams, fewer layers of approval, and executives who communicate directly with employees responsible for paying invoices.
That efficiency is good for business—but attackers can exploit it.
Imagine an accounting employee receiving an email that appears to be from the company president:
"I already approved the invoice below. Please get this processed today."
Under that message is a professionally formatted invoice and an apparent email chain showing previous discussions with the vendor.
There might not be a malicious attachment.
There might not be a request for a password.
There might not even be a link to click.
The employee simply sends the payment.
That is one reason the FBI describes business email compromise as one of the most financially damaging forms of online crime.
Technology Alone Cannot Stop Invoice Fraud
Email security remains extremely important.
Microsoft recommends layered controls including properly configured email authentication, spoof protection, advanced anti-phishing technology, and security platforms such as Microsoft Defender for Office 365. Microsoft's security tools can also remove messages after delivery when new threat intelligence identifies them as malicious.
But businesses also need operational controls.
An email filter cannot determine whether your accounting employee should legitimately send $47,000 to a new bank account.
That requires a business process.
What Businesses Should Do Now
Require independent verification of payment requests
Any significant payment, new vendor, or change in banking information should be confirmed through a second communication channel.
The FBI specifically recommends verifying payment and purchase requests by contacting the person making the request and independently confirming changes to account numbers or payment procedures.
If an email says a vendor changed banks, do not call the telephone number contained in that email.
Use the vendor contact information your company already has on file.
Use dual approval for large transactions
One employee should not be able to receive, approve, and release a significant payment without another person reviewing it.
Even a simple two-person approval process can stop an expensive mistake.
Protect executives against email impersonation
Executives are frequent impersonation targets because their names, titles, email formats, and company relationships are often publicly available.
Organizations using Microsoft 365 should review anti-phishing and impersonation protection policies and ensure important executives and high-risk users receive appropriate protection.
Configure SPF, DKIM, and DMARC
These email authentication technologies make it harder for criminals to successfully spoof your company's legitimate domain.
They are not complete solutions by themselves, but they are important components of a layered email-security strategy.
Microsoft specifically recommends properly configuring email authentication as part of protection against executive impersonation and invoice fraud.
Require multifactor authentication
MFA helps reduce the chance that stolen credentials can be used to take over legitimate employee email accounts.
CISA recommends MFA for business email, file storage, remote access, and especially administrative accounts, with phishing-resistant authentication preferred when available.
Train accounting staff differently
Traditional annual phishing training is not enough.
Employees who handle money need specific training around:
- Bank-account changes
- ACH requests
- Wire transfers
- Executive requests
- Payroll changes
- Vendor invoices
- Gift cards
- Urgent payment requests
Accounting employees should feel comfortable slowing down a transaction—even when the email appears to come from the CEO.
Review unusual payment requests outside email
One of the simplest security controls is also one of the most effective:
Pick up the phone.
The FTC recommends clear invoice-approval procedures and specifically advises businesses to carefully review invoices before paying them.
Cybersecurity Is Becoming a Business-Process Problem
The biggest lesson from this campaign is that cybersecurity cannot remain exclusively an IT responsibility.
Your firewall cannot approve an invoice.
Your antivirus cannot determine whether the CEO actually authorized a payment.
Your email filter cannot always know whether a perfectly written message represents a legitimate business transaction.
Security increasingly requires coordination between:
IT + Accounting + Management + Employees
Technology reduces risk.
Business processes catch what technology misses.
The strongest organizations use both.
How MicroAdvantage Can Help
At MicroAdvantage, we help businesses evaluate cybersecurity across the entire environment—not just individual computers.
That can include reviewing:
- Microsoft 365 security
- Microsoft Defender for Office 365
- Email anti-phishing and impersonation protection
- SPF, DKIM, and DMARC configuration
- Multifactor authentication
- Conditional Access
- Endpoint detection and response
- Administrative account security
- Firewall and network configuration
- Backup and disaster recovery
- Security awareness practices
- Remote-access security
We can also help identify security gaps that may allow a simple phishing message to become a larger network or financial incident.
If you're not sure whether your Microsoft 365 environment, email security, or business infrastructure is properly protected, MicroAdvantage can help review your environment and identify where additional safeguards may be needed.
Sources
Microsoft Security Research — Protecting organizations from AI-assisted executive impersonation and invoice fraud, published September 10, 2026. Read Microsoft's security research
FBI — Business Email Compromise, including guidance for identifying and verifying fraudulent payment requests. FBI Business Email Compromise guidance
Federal Trade Commission — Run a small business? Pay your bills, not scammers, with practical guidance for recognizing fake invoices. FTC small-business invoice scam guidance
CISA — Require Multifactor Authentication, cybersecurity guidance for small and midsize businesses. CISA MFA guidance