Microsoft Analyzes BEC Campaign Impersonating Executives and Using ServiceNow Invoices

Microsoft detected more than one million fraudulent emails impersonating company executives and ServiceNow communications. Indicators suggest possible use of generative AI, but they are not definitive evidence.

The Microsoft BEC campaign, which the company observed from August 3 to 5, 2026, involved more than one million fraudulent emails. The attackers posed as senior executives at target companies and asked accounting departments to make ACH payments of approximately $50,000. In its analysis, Microsoft found signs consistent with the use of generative AI to prepare the templates, but did not definitively confirm its involvement.

According to Microsoft, 87.7% of the intercepted messages were directed to users in the United States. The campaign falls into the business email compromise (BEC) category—scams that do not necessarily rely on technically compromising systems, but instead on convincingly impersonating a trusted person or organization.

BEC Campaign Used Invoices and Fake Threads

The attackers posed as CEOs, CFOs, or presidents of the target companies. The payment request was accompanied by a forged invoice and an allegedly forwarded communication thread designed to resemble communications with ServiceNow.

The lookalike domain service-nowinc[.]com was registered on July 31, 2026, according to WHOIS, shortly before the observed campaign.

Microsoft explicitly stated that it found no evidence of compromise involving ServiceNow or other legitimate organizations whose names and brands were misused in the lures. This was therefore not a confirmed breach of ServiceNow systems, but rather the misuse of its identity in a social engineering scam.

AI Indicators Do Not Confirm Attribution

In the analyzed messages, Microsoft observed excessive HTML comments and a uniform template structure. It identified these elements as indicators consistent with AI-assisted content creation. However, the available findings do not provide definitive evidence that the attackers actually used generative AI.

Microsoft also did not publicly attribute the activity to a specific threat group. It is also unknown how many recipients made the requested payment or what financial losses the campaign caused.

Verify Payments Outside Email

The case illustrates a combination of several known BEC techniques: impersonating an executive, misusing a vendor’s name, attaching an invoice, and creating a fake communication history. The appearance of the email, invoice, or alleged thread alone is therefore not sufficient to confirm a payment request.

Microsoft recommends using email authentication, anti-spoofing protection, and mechanisms for removing messages after delivery. For financial teams, it is essential to independently verify changes to payment details or unusual requests through a previously known contact or another agreed-upon channel.

The company published indicators of compromise, including related technical data. Further developments will show whether new waves of this activity, additional domains, sender accounts, or bank details emerge.

Sources

  • Microsoft Security Blog – Microsoft’s primary analysis confirms the campaign’s scale, the lures used, the absence of evidence of a ServiceNow compromise, the limited assessment of possible AI use, and the published mitigations.
  • Verisign WHOIS record provided through Alibaba Cloud – Independently supports the July 31, 2026 registration date for the service-nowinc.com domain and the registrar, Squarespace Domains LLC.

Verified and updated: 09/11/2026 06:26

Sharing