Redpacketsecurity AI-Enhanced Invoice Fraud Campaign Targets Organizations
Article Content
- •Over a million fraudulent emails sent, targeting U.S. organizations.
- •Attackers impersonated CEOs to request ACH payments of nearly $50,000.
- •AI was used to enhance email templates and narratives, increasing legitimacy.
In early August 2026, Microsoft detected a sophisticated email fraud campaign targeting organizations, leveraging AI to create convincing impersonation emails. The attackers sent over a million fraudulent emails, primarily to U.S. users, impersonating CEOs and requesting ACH payments of nearly $50,000. The emails included fabricated threads and invoices to enhance legitimacy. This campaign utilized third-party email services and showcased advanced tactics, including layered social engineering techniques. Microsoft noted that the use of AI allowed for improved email templates and narratives, making the scams more believable. The attack highlights the evolving nature of business email compromise (BEC) scams, which are becoming more sophisticated and scalable. Microsoft researchers emphasized the need for organizations to enhance their security measures against such evolving threats.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (8)
Following this threat?
Track AWS in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Outsider Phishing Kit Continues Operations Post-Takedown The Outsider Phishing Kit, operated by the threat actor ChenLun, has shown resilience despite significant takedown efforts. Group-IB researchers reported over 700 new phishing pages created within a month following a civil lawsuit filed by Google against the group on June 12, 2026. The kit has been linked to over…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…