Threat Intelligence

Microsoft Warns of AI-Powered CEO Fraud and Passkey Phishing Targeting Cloud Accounts

The Hacker News · 13 Sept 2026
Key Takeaway Verify any payment request or invoice change through a separate, known contact method before transferring funds, especially if it references an executive by name.

Microsoft has disclosed two separate attack campaigns hitting businesses through fraudulent email and account takeover tactics. The first, run over just three days in early August 2026, saw attackers send more than a million scam emails impersonating company CEOs. The messages pushed accounts payable staff to approve fake ServiceNow subscription invoices via ACH bank transfers, targeting US firms in IT services, consumer goods, real estate and manufacturing.

What makes this campaign notable is its layered approach. Rather than relying on a single fake invoice, attackers combined executive impersonation, forged email threads, vendor branding and fabricated supporting conversations into one convincing narrative. They researched real CEOs, CFOs and presidents at target companies and inserted their names into email signatures, while registering lookalike domains to appear legitimate. Microsoft also noted signs that generative AI was used to draft tailored email templates, making the scam messages harder to spot as fraudulent.

Microsoft separately flagged a second campaign using passkey-themed social engineering to compromise Microsoft cloud accounts and exfiltrate data, though full details of that attack were not covered in this excerpt. Both campaigns highlight how attackers are combining trusted infrastructure, brand impersonation and AI tools to make fraud attempts more convincing than traditional business email compromise scams.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.