Skip to content
Tech News
← Back to articles

Threat Actor Generates 1M Personalized Fraud Emails in 3 Days

read original get YubiKey 5 NFC Security Key → more articles
Why This Matters

Microsoft tracked a phishing operation that pushed over a million personalized fraud emails in three days, using AI to tailor invoices and even fabricate executive email threads. It shows generative AI is collapsing the old tradeoff between phishing volume and believability, putting finance teams at heightened risk of ACH fraud.

Key Takeaways
Worth a Look

YubiKey 5 NFC Security Key — When AI-generated phishing emails get this convincing, a hardware security key is one of the few defenses that still holds up — a stolen password alone won't get an attacker into your accounts. The YubiKey 5 NFC works with major services and business logins, and taps to phones over NFC or plugs into USB-A. It's a pocket-sized way to make credential phishing a dead end.

See YubiKey 5 NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Artificial intelligence (AI) is enabling threat actors to send unholy volumes of fraudulent emails, personalized to a degree that mass emailers of old couldn't have touched.

Last month, Microsoft researchers tracked a phishing campaign in which an unattributed threat actor sent out more than one million emails in just three days. Despite the volume of content they had to juggle, the threat actor managed to specifically target relevant accounts payable departments and lightly personalize each message with the real names of targeted employees' executive leadership, most likely through serious assistance from AI. A few other bells and whistles, too, made the emails much more convincing than your average Automated Clearing House (ACH) fraud scam.

Personalized Mass Phishing

The basic premise of the emails was that victims' companies owed just shy of $50,000 to the enterprise cloud services company ServiceNow for an annual subscription. Attached invoices were detailed — with credible line items and dollar amounts that didn't add up to round numbers — and featured visual elements and branding true to the impersonated company.

Related:Papercut AI Swarm Attack Heralds Changes for Cyber Kill Chain

In a clever little twist, the attacker wrapped each phishing email and invoice in a forged email "thread." They created a brief back-and-forth conversation, made to seem like it occurred before the victim received the email, between an executive at a victim's company and the president of ServiceNow. The executive asked their colleague at ServiceNow to forward the invoice directly to the victim in their finance department.

A sample of a spoofed message from an executive team member in a massive ACH scam campaign. SOURCE: Microsoft

To give extra credence to these exchanges, the attackers identified CEOs, CFOs, and presidents at victim organizations, and plugged them into the phishing emails' signatures. It would've been an easy task to throw at a chatbot.

"Gathering information about a victim organization can now be a matter of minutes," says Merium Khalid, director of AI and automation for the Office of the CTO at Barracuda Networks. "AI can rapidly process publicly available information on the internet about an organization — such as company websites, executive information, employee roles, press releases, and other public sources — and use that context to help construct more convincing impersonation emails."

She adds that attackers can build multiple AI-driven processes for different parts of a campaign, including information gathering, generating personalized content, and creating templates that can be used for a variety of targeted organizations. Indeed, Microsoft found a few telltale signs that the threat actor behind this mass email campaign used AI to assist in personalizing its email template to specific victims.

... continue reading