
The invoice scam that brings its own proof
An email lands in the accounts payable inbox on a Tuesday morning. It appears to come from the chief executive, and it approves an invoice for just under 50,000 dollars. Beneath the signature sits a forwarded chain in which that same chief executive and the supplier's president discuss the purchase. Everything a careful person would go looking for before releasing money is already on the screen. None of it is genuine.
Microsoft's threat intelligence team published research on 10 September describing a campaign built on precisely that idea. Between 3 and 5 August, Microsoft detected more than a million emails aimed at enterprise users, with 87.7 per cent of them sent to recipients in the United States. The messages impersonated executives at the targeted companies themselves, including chief executives, chief financial officers and presidents, and pressed accounts payable teams to release an ACH payment of nearly 50,000 dollars for what was presented as an annual subscription to a well known software platform.
One point of accuracy matters here. Microsoft states that it found no evidence that the legitimate organisations named in the lures, including the software vendor being impersonated, were compromised or involved. The campaign ran on lookalike domains and fabricated content.
The lure arrives carrying its own corroboration
Most invoice fraud rests on a single claim: pay this, to this account, now. This campaign stacked four separate fabrications into one message so that each appeared to support the others.
The first layer was the executive, who appeared in the sender display name, the reply-to display name and the email signature, complete with name and email address. The second was the instruction, kept short and flat: an approval of "the invoice below", with an offer to send a PDF version on request.
The third layer was the invoice itself, sitting immediately under the signature as forwarded content. Microsoft describes it as detailed and professional looking, with vendor branding and logos, an invoice number, issue and due dates, currency, amount due and itemised lines. The payment instruction was a bank transfer to accounts controlled by the attacker, and Microsoft saw several different financial institutions across samples, which suggests the destination varied by target. Parts of the document were personalised, with the recipient's company name and executive name filled into the "billed to" section.
The fourth layer was the conversation. Below the fake invoice sat two more forwarded messages in which the two spoofed executives appeared to discuss the purchase, its implementation and how the invoice should be handled.
That last layer is the interesting one. When a payment request looks unusual, the normal human response is to look for supporting context. Is there any history here? Did anyone senior actually agree to this? A fabricated thread answers both questions before they are asked, without the reader having to go anywhere.
Why the delivery route matters
The volume came from somewhere ordinary. Microsoft reports that the attacker used multiple third-party email service accounts rather than standing up infrastructure of its own. Bulk email platforms exist to get mail delivered reliably, which is what makes them attractive to someone sending a million fraudulent messages.
Preparation had started days earlier. A lookalike domain impersonating the software vendor was registered on 31 July, shortly before the activity began, and was used for the spoofed vendor president's address and as the contact address printed on the fake invoice. A second domain registered the same day appeared in the reply-to field.
Microsoft's mitigation advice points at the consequence. Alongside SPF, DKIM and DMARC, it directs defenders to how mail flow connectors are configured, so mail arriving through a third-party service is judged on its merits rather than its route.
The seams were still visible
The content was convincing without being perfect, and the flaws Microsoft lists are the kind a finance team can be taught to notice.
- The "from" lines inside the forwarded thread lacked the date headers that real forwarded email carries.
- Genuine reply chains are normally indented or visually grouped as they go back in time. Here the older messages were simply left aligned, like body text.
- Sender display names did not match the underlying sender addresses, and subject lines leaned on financial keywords, with at least one sample carrying a plain spelling error.
- The wording was slightly off in places, including a request along the lines of "no need to copy me".
- The story contradicted itself. In one thread the chief executive asked not to be copied in, while the most recent message claimed the invoice was approved and had been sent from his own address.
The AI markers, and what they are worth
Microsoft observed several indicators consistent with AI-assisted template development, including unusually verbose HTML comments, structured section labelling and highly uniform template construction. It also notes that em dashes and long banner rows of equals signs have become associated with AI generated content.
Microsoft is careful about how far that goes, and so should the rest of us be. The company states that while these indicators suggest generative AI involvement, they do not independently establish how much of the content AI produced. Plenty of people write em dashes, and treating punctuation as proof of fraud produces noise rather than safety. The more useful signal is that invoice identifiers and narrative structure stayed largely consistent across samples while organisation specific details changed, which points to templated generation at scale.
What to do about it
- Verify out of band, as a rule rather than a judgement call. The NCSC's business payment fraud guidance is direct: contact the supplier on official details you already hold, not details supplied in the message. For large sums, send a small test payment and confirm receipt first.
- Limit who can change payment details. Only designated people should be able to alter payment arrangements, and any change should be verified independently of the request that prompted it.
- Treat a forwarded thread as content, not evidence. Anything that appears inside an email was typed by whoever sent that email. A chain of replies is no more verified than the message wrapped around it.
- Remove the seniority pressure. Publish an internal rule that no executive will ever approve a payment purely by email, and say so out loud at board level. That gives an accounts payable clerk explicit permission to stop.
- Make reporting quick and worth doing. Finance inboxes need a one-click way to report a suspicious payment request, and a prompt answer when they use it. Silence trains people to stop bothering.
- Cover the technical ground. Configure email authentication, check filtering for mail routed through third-party connectors, make sure you can pull messages back after delivery, and monitor for fresh domain registrations that mimic your name or your suppliers.
The bottom line
Business email compromise accounted for about 3.04 billion dollars in reported losses in the FBI's 2025 Internet Crime Report, second only to investment fraud. It stays near the top of that table because it needs no vulnerability, no malicious attachment and no compromised mailbox. It needs a plausible story and a payment process that will accept one.
What has changed is the effort required to make the story hang together. Producing a branded invoice, a matching signature block and a short executive conversation used to take real work. It now takes very little, and it can be personalised to thousands of organisations at once. The countermeasure has not changed: a payment verified through a channel the attacker does not control is a payment that does not go astray.
The person most likely to catch this sits in finance, not in the security team. Give them a process that expects them to stop and check, and the recognition when they do.
Phishing Tackle offers the tools businesses need to strengthen their human risk strategies, with multi-platform testing, real-time behavioural insights, and actionable data to keep your organisation ahead of modern cyber threats.
Contact us today to learn how Phishing Tackle can help safeguard your organisation from the growing array of cyber risks.
