HomeInsightsAI Security
AI security · 9 min read

A Million Fake CEO Emails Went Out in Three Days

Microsoft disclosed on 10 September 2026 that attackers sent more than a million emails impersonating chief executives between 3 and 5 August, using generative AI to draft them alongside fabricated invoices and forged email threads, chasing ACH payments of roughly $50,000. A second campaign phones employees pretending to be the IT help desk to defeat passkeys. Both are cheap to block.

The email arrives on a Tuesday. It is from your chief executive, it references a ServiceNow subscription renewal, and there is a thread above it where two colleagues have already discussed the payment. An invoice is attached. The amount is just under fifty thousand.

The tone is right. The formatting matches the last email you got from them. The thread reads like a normal internal conversation that you were simply added to late.

None of it is real. Not the thread, not the colleagues in it, not the invoice, and not the chief executive. And between 3 and 5 August 2026, more than a million versions of that email went out.

What actually happened

Microsoft disclosed the campaign on 10 September 2026. Over a three day window, attackers sent more than a million scam emails impersonating chief executives, chief financial officers, and company presidents, aimed specifically at accounts payable staff.

The ask was always the same shape: process an ACH payment of nearly $50,000 for a ServiceNow subscription that did not exist. Targets were enterprise users across IT services, consumer goods, real estate, and manufacturing in the United States, and the attackers abused third-party email infrastructure to get the volume out.

The part that matters is the construction. The attackers used generative AI to draft the email templates, then supported them with fabricated invoices and forged email threads. That last element is the one that defeats the advice most people have been given, because the standard guidance is to be suspicious of unexpected payment requests, and this request does not arrive unexpectedly. It arrives at the bottom of a conversation that appears to have been going on without you.

Fifty thousand is also a deliberate number. It is large enough to be worth the effort and small enough to sit inside the routine approval authority of a mid-level finance person at a reasonable-sized company. Attacks asking for half a million get escalated. Attacks asking for fifty thousand get processed.

Why AI made this work

Business email compromise is not new. What changed is the economics, and the economics are the whole story.

The old version of this attack required a person to research a target company, learn who the executives were, study how they wrote, and compose a convincing message. That is perhaps an hour of skilled work per target, which puts a hard ceiling on volume and pushes attackers toward large organisations where the payoff justifies the effort. Small businesses were protected by being insufficiently worth the trouble.

Generative AI removes that ceiling entirely. Drafting a thousand personalised, well-written, contextually plausible emails now costs almost nothing, which means the attacker no longer has to choose targets by value. They can target everyone and let the response rate sort it out. A million emails in three days is not a sophisticated operation, it is an ordinary operation with the labour cost removed.

This is the same shift we described in AI deepfake scams and voice cloning fraud, and it keeps arriving in new forms because the underlying change is not about any particular technique. Every fraud that was previously limited by how much human attention it required has become cheap, and fraud that is cheap gets pointed at everyone.

The forged thread deserves particular attention because it targets a specific human instinct. We evaluate a message partly by its context, and a message sitting beneath an apparent conversation inherits credibility from that conversation. Generating a plausible fake thread used to be laborious. It is now a prompt.

Not sure whether your payment process would catch a convincing fake? A €49 audit reviews your approval flow and finds the gaps.

The passkey attack is the clever one

The second campaign Microsoft disclosed has been running since May 2026 and is more interesting, because it attacks something everyone has been told is the safe option.

Passkeys are genuinely phishing-resistant. They are bound to a specific site, so a fake login page cannot capture anything useful, and they remove the entire category of attack that relies on stealing a password. The advice to move to passkeys is good advice and this campaign does not change it.

What the attackers do instead is call. They phone or message employees on their personal phones, pose as internal IT help desk staff, and walk them through updating their passkey, MFA, or SSO settings. The technology is never defeated. The person is persuaded to approve a legitimate authentication request that the attacker initiated, which the system correctly processes because from its perspective the real user genuinely approved it.

That is the key insight for anyone who has been treating passkeys as a solved problem. A phishing-resistant credential does not protect you from a user who has been talked into using it on the attacker's behalf. The attack moved from the login page to the phone call, and the phone call is not something your identity provider can filter.

The personal phone detail is not incidental either. Calling a personal mobile takes the conversation outside every monitored channel your business controls, and it arrives in a context where people are less guarded than they are at their desk.

What the numbers say about small businesses

The Microsoft campaigns targeted enterprises, which makes it tempting to file this under other people's problems. The broader data argues otherwise fairly forcefully.

Roughly one in four malicious data breaches is now AI-powered, a 56% increase year over year, and AI-enabled breaches cost an average of $6 million, about $1 million more than the overall average. Those are enterprise figures and they describe the direction rather than your exposure.

The small business figures are the relevant ones and they are worse. Incident rates are up 47% year over year, roughly 80% of small businesses suffered at least one cyberattack in 2025, and 41% of those incidents were AI-driven. Average breach losses approach $254,000. Around 88% of small business breaches involve ransomware, against 39% for large organisations, which tells you attackers correctly assume smaller targets have weaker recovery options.

The figure that should focus attention is that roughly 60% of attacked small firms close within six months. Treat that as directional rather than precise, because survivorship statistics in this area are notoriously difficult to measure well. Even discounted heavily it describes a category of event that a small business does not recover from the way a large one does.

The fix that costs nothing

Here is the genuinely good news, and it is the reason this article is worth ten minutes rather than being another entry in an anxiety pile.

Every version of the invoice fraud attack, however well written, depends on the payment being approved through the channel the request arrived in. The email is convincing, the invoice looks right, the thread reads as genuine, and none of it survives one phone call to a number you already had.

So the rule is one sentence: any payment above a threshold you set gets verbally confirmed with the requester, using contact details you already hold, not details from the message. Not a reply to the email, because the attacker controls that. Not the number on the invoice, because the attacker wrote it. The number in your own records, dialled by the person who would otherwise be making the payment.

That single control defeats the entire category, including versions using deepfaked voice and video, because it is out-of-band. The attacker has to compromise a second independent channel to beat it, which is a completely different level of effort from sending a good email. Set the threshold somewhere that makes sense for your business, make it non-negotiable regardless of how urgent the request appears, and write it down so it survives the person who currently knows it leaving.

And name the urgency itself as the warning sign. Every version of this attack applies pressure, because pressure is what stops people pausing to check. A genuine supplier payment can wait twenty minutes for a phone call. Treat any request that cannot as suspicious by definition, which turns the attacker's main tool into a detection signal.

Defending against the help desk call

The passkey campaign needs a different answer, and it is equally cheap.

Establish that your IT support, whether internal or an outside provider, never calls staff unprompted to walk them through authentication changes. Then tell your team that rule explicitly, because the attack works on people who do not know what normal looks like and therefore cannot recognise abnormal. Most staff have no idea whether an unexpected call from IT is routine, and in the absence of a rule they default to being helpful.

Give them a specific action rather than a vague instruction to be careful. If someone calls about your login, hang up and ring the number you already have for support. That is not rude, it is procedure, and framing it as procedure removes the social cost that stops people doing it. The single largest reason these calls succeed is that hanging up on someone who sounds professional feels impolite.

Finally, be clear that approving an authentication prompt you did not personally initiate is the thing never to do. Passkeys and MFA both work on the assumption that approval means intent. If a prompt appears and you were not in the middle of logging in, the correct response is always to decline and then report it, regardless of how reasonable the explanation on the phone sounds.

None of this requires a security budget, a product, or a consultant. It requires deciding the rules once, telling people plainly, and writing them somewhere a new hire will find them. The attackers have industrialised the cheap part of fraud, and the defence that still works is the boring, human, out-of-band check they cannot automate their way around.


Sources

Quick answers

Common questions.

Want this in your business?

The €49 audit shows you exactly which automations would pay back fastest in your specific operation.

€49 entryFull AI audit + strategy call included

Reserve your auditNo commitment. No contracts. Just clarity.