Microsoft has uncovered two social engineering campaigns targeting businesses through executive impersonation and fraudulent passkey notifications. The attacks show how cybercriminals are combining artificial intelligence, trusted communication services, and convincing impersonation tactics to steal money and compromise cloud accounts.
In the first campaign, attackers distributed more than one million scam emails between August 3 and August 5, 2026. Nearly 88% of the messages targeted users in the United States, primarily within the IT services, consumer goods, real estate, and manufacturing industries. The emails impersonated company executives and instructed accounts payable employees to send ACH payments of nearly $50,000 for fake ServiceNow annual subscriptions.
To make the requests appear legitimate, the scammers used lookalike domains, fabricated invoices, fake executive signatures, and invented email conversations. Microsoft found signs suggesting generative AI may have helped the attackers develop consistent email templates and personalize their messages. However, Microsoft found no evidence that ServiceNow or the other impersonated organizations were compromised. Microsoft’s investigation indicates that the criminals used attacker-controlled infrastructure to imitate trusted companies.
A separate campaign used urgent calls, text messages, and Microsoft Teams communications claiming that employees needed to update a passkey, MFA method, or single sign-on configuration. Victims were directed to convincing phishing pages or legitimate device-code authentication screens. After gaining access, the attackers could register their own authentication method, search Microsoft Graph, and collect information from Outlook, SharePoint, and OneDrive. Microsoft reported observing this cloud intrusion activity since May 2026.
Organizations should require independent verification for payment requests, especially when an executive demands an urgent ACH transfer. Finance teams should confirm invoices using a trusted phone number instead of replying to the original message. Security administrators should also enforce SPF, DKIM, and DMARC, monitor newly registered MFA methods, investigate unusual Microsoft Graph activity, and revoke active sessions immediately after a suspected account compromise.

