Business email compromise is getting harder to spot because criminals are getting better at telling a believable story.
Microsoft recently documented a large campaign that sent more than one million phishing emails over just a few days. The messages impersonated executives, vendors, and routine business processes, often leading victims toward ACH payment requests approaching $50,000.
Microsoft also found indicators suggesting generative AI may have been used to help create or refine parts of the campaign. That does not mean AI was proven to have generated every message. It does mean small businesses should expect payment fraud to become more polished, more personalized, and more convincing.
The practical lesson is simple:
If a payment request arrives by email, the email itself should never be the only proof that the request is legitimate.

What Microsoft Found
Microsoft reported a campaign active from August 3 through August 5, 2026 that sent more than one million emails. Roughly 87.7% of the messages targeted recipients in the United States.
The campaign used executive impersonation, vendor branding, fake invoice threads, and realistic business language. Some messages appeared to involve a ServiceNow invoice, while others created the impression that an executive had already approved a payment.
The payment requests often pushed victims toward ACH transfers in amounts near $50,000.
Where Does AI Enter the Picture?
Microsoft identified indicators consistent with AI-assisted content generation, including polished wording and message variations that could be produced quickly at scale.
That is important, but it should not be overstated.
There is no proof that AI alone created the entire campaign. The safer conclusion is that criminals can now use generative AI to make business email fraud faster, cheaper, and more convincing.
AI can help attackers:
- Rewrite messages to sound more natural
- Adjust tone for different targets
- Create believable vendor conversations
- Generate polished invoice language
- Scale many variations of the same scam
The Dangerous Part Is the Story
Many small businesses train employees to look for bad spelling, strange grammar, or obvious scam language.
That is no longer enough.
The modern attack may include a believable executive name, a realistic vendor reference, a fake email thread, and an invoice that looks normal.
The attacker is not only trying to steal a password.
They are trying to make the employee believe a business process has already happened.
“The boss approved it.”
“The vendor is waiting.”
“Accounting needs this paid today.”
That is process hacking.
For more guidance on what to do and how to respond to an email attack the FBI has a few pointers to offer here.
Small Businesses May Have a Particular Weakness
Small companies often have short approval chains.
The owner may directly email the bookkeeper.
The office manager may regularly pay vendors.
Employees may know each other well enough that an urgent request from the boss feels normal.
That trust is valuable inside a small team.
It can also be exploited.
An attacker does not need to fool twenty departments. They may only need to fool one person who can send money.
A Password Manager Cannot Fix This by Itself
Strong passwords, MFA, passkeys, and password managers remain essential.
However, this type of fraud can succeed even when the attacker never steals a password.
If the employee believes the request and sends the money voluntarily, identity security alone cannot stop the transaction.
That is why payment controls matter just as much as account security.
Create a Second Channel for Payment Verification
Every small business should establish a simple rule:
Large, unusual, or changed payment requests must be verified through a second trusted channel.
That means the employee should not reply to the same email thread and ask, “Is this really you?”
Instead, they should call a known phone number, speak to the owner in person, use a known Teams account, or verify through another established company method.
The second channel should be independent of the message that created the request.
Give Payments a Simple Approval Rule
A practical small-business policy could require secondary approval for:
- New vendors
- Changed bank account details
- Large ACH transfers
- Wire transfers
- Urgent payments outside normal procedure
- Invoices that arrive from a new email address
- Requests that bypass the usual approval process
The dollar threshold will vary by company.
The important part is that employees know the rule before a suspicious request arrives.
Check the Actual Email Address
Display names are easy to fake.
A message may show the owner’s name while coming from a lookalike address.
Employees should check the full sender address, especially when money or account changes are involved.
Look for:
- Misspelled domains
- Extra letters
- Unexpected free email accounts
- Recently changed vendor addresses
- Reply-to addresses that differ from the sender
This does not catch every attack, but it can expose many common ones.
Email Security Still Provides an Important Layer
Business procedures are essential, but technical controls still matter.
Small businesses should use:
- SPF
- DKIM
- DMARC
- MFA
- Secure email filtering
- Endpoint protection
- Managed monitoring
These controls can reduce spoofing, detect suspicious messages, and make account compromise more difficult.
They should support employee verification, not replace it.
What Should a Small Business Do This Week?
- Set a payment-verification rule.
- Choose a second trusted verification channel.
- Define which payments need extra approval.
- Train employees not to rely on display names.
- Review MFA and email security settings.
- Make sure staff know who to call when a request feels unusual.
Frequently Asked Questions
No. Microsoft identified indicators consistent with generative AI use, but that is not the same as proving AI generated every message in the campaign.
There is no evidence that ServiceNow itself was compromised in this campaign. Attackers used ServiceNow-related branding and invoice themes as part of the social-engineering story.
Microsoft documented ACH payment requests approaching $50,000 in some cases.
Business email compromise, or BEC, is fraud that impersonates a trusted person or organization to convince employees to send money, change payment information, reveal data, or take another harmful action.
MFA can reduce account takeover risk, but it cannot stop an employee from voluntarily sending money after believing a fake payment request.
Contact the bank or payment provider immediately, notify your IT or cybersecurity provider, preserve the email and related evidence, and begin incident-response procedures. Speed matters.
Make “Verify Before You Pay” Part of Your Security Plan
AI is making business email fraud more convincing, but the defense does not need to be complicated.
A simple verification rule can interrupt the attack before money leaves the account.
SofTouch Systems helps small Texas businesses improve email security, identity protection, employee awareness, and practical IT procedures.
If you are unsure whether your current payment-verification and email-security practices are strong enough, start with a free 15-minute IT security check.
Verify before you pay. Then make sure your employees know exactly how.
Discover more from SofTouch Systems
Subscribe to get the latest posts sent to your email.
