Microsoft Warns of AI-Powered CEO Fraud and Passkey Phishing Targeting Cloud Accounts
Microsoft has disclosed two separate attack campaigns hitting businesses through fraudulent email and account takeover tactics. The first, run over just three days in early August 2026, saw attackers send more than a million scam emails impersonating company CEOs. The messages pushed accounts payable staff to approve fake ServiceNow subscription invoices via ACH bank transfers, targeting US firms in IT services, consumer goods, real estate and manufacturing.
What makes this campaign notable is its layered approach. Rather than relying on a single fake invoice, attackers combined executive impersonation, forged email threads, vendor branding and fabricated supporting conversations into one convincing narrative. They researched real CEOs, CFOs and presidents at target companies and inserted their names into email signatures, while registering lookalike domains to appear legitimate. Microsoft also noted signs that generative AI was used to draft tailored email templates, making the scam messages harder to spot as fraudulent.
Microsoft separately flagged a second campaign using passkey-themed social engineering to compromise Microsoft cloud accounts and exfiltrate data, though full details of that attack were not covered in this excerpt. Both campaigns highlight how attackers are combining trusted infrastructure, brand impersonation and AI tools to make fraud attempts more convincing than traditional business email compromise scams.