What is confirmed
Microsoft detected more than a million emails sent between 3 and 5 August through third-party mail services, with fake executive conversations and a fabricated invoice impersonating ServiceNow.
The messages sought ACH transfers of about $50,000 to attacker-controlled accounts; Microsoft does not report a million payments.
What it means
Lookalike domains and fabricated message threads create the appearance of prior approval.
HTML comments and highly uniform templates are consistent with AI assistance but do not quantify its role.
What to do
Independently confirm any changed bank account or urgent invoice with known supplier and executive contacts.
Check the sending domain, headers and actual email thread; pause payment if anything conflicts.
Use the related SecurCheck tool, then confirm important decisions with an official source.


