Microsoft detected an AI-assisted business email compromise and invoice-fraud campaign that sent more than one million emails from August 3–5, primarily targeting U.S. enterprise users. The attackers impersonated executives at victim organizations and ServiceNow, targeting accounts-payable personnel with fabricated invoices and forged email threads intended to prompt ACH transfers of nearly $50,000.
The campaign used third-party email-delivery accounts and newly registered lookalike domains to make the payment requests appear legitimate. Microsoft found no evidence that ServiceNow or any other organization impersonated in the lures had been compromised or participated in the activity. Campaign artifacts indicated AI-assisted development of phishing templates, though Microsoft could not conclusively determine the extent to which AI generated the messages; organizations should ensure anti-phishing controls and automated attack-disruption capabilities in Microsoft Defender XDR are configured to contain comparable BEC activity.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft identified service-nowinc[.]com, domainlify[.]net, and associated sender addresses as campaign indicators, and found template features consistent with AI-assisted development. Microsoft found no evidence that ServiceNow or other impersonated organizations were compromised or involved.
An invoice-fraud phishing campaign sent more than one million messages, primarily to U.S. enterprise users and accounts-payable staff. The messages impersonated executives and ServiceNow, using fabricated invoices and forged email threads to seek ACH payments of nearly $50,000.
The threat actor registered service-nowinc[.]com and domainlify[.]net, later using them in spoofed ServiceNow contact details and Reply-To addresses.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 21 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
7 references tracked. Mallory keeps watching after this page renders.
decipher.sc
Open sourcetherecord.media
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcemalware.news
Open sourcemicrosoft.com
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.