Your Boss Approved This Invoice. Or Did They? AI Is Changing Business Email Fraud

SofTouch Systems banner showing AI-driven invoice fraud and a suspicious payment request being reviewed before approval.

Business email compromise is getting harder to spot because criminals are getting better at telling a believable story.

Microsoft recently documented a large campaign that sent more than one million phishing emails over just a few days. The messages impersonated executives, vendors, and routine business processes, often leading victims toward ACH payment requests approaching $50,000.

Microsoft also found indicators suggesting generative AI may have been used to help create or refine parts of the campaign. That does not mean AI was proven to have generated every message. It does mean small businesses should expect payment fraud to become more polished, more personalized, and more convincing.

The practical lesson is simple:

If a payment request arrives by email, the email itself should never be the only proof that the request is legitimate.

SofTouch Systems banner showing AI-driven invoice fraud and a suspicious payment request being reviewed before approval.
AI is making invoice fraud and business email compromise harder to spot. Small businesses should verify payment requests through a second trusted channel before sending money.

Microsoft reported a campaign active from August 3 through August 5, 2026 that sent more than one million emails. Roughly 87.7% of the messages targeted recipients in the United States.

The campaign used executive impersonation, vendor branding, fake invoice threads, and realistic business language. Some messages appeared to involve a ServiceNow invoice, while others created the impression that an executive had already approved a payment.

The payment requests often pushed victims toward ACH transfers in amounts near $50,000.


Microsoft identified indicators consistent with AI-assisted content generation, including polished wording and message variations that could be produced quickly at scale.

That is important, but it should not be overstated.

There is no proof that AI alone created the entire campaign. The safer conclusion is that criminals can now use generative AI to make business email fraud faster, cheaper, and more convincing.

AI can help attackers:

  • Rewrite messages to sound more natural
  • Adjust tone for different targets
  • Create believable vendor conversations
  • Generate polished invoice language
  • Scale many variations of the same scam

Many small businesses train employees to look for bad spelling, strange grammar, or obvious scam language.

That is no longer enough.

The modern attack may include a believable executive name, a realistic vendor reference, a fake email thread, and an invoice that looks normal.

The attacker is not only trying to steal a password.

They are trying to make the employee believe a business process has already happened.

“The boss approved it.”

“The vendor is waiting.”

“Accounting needs this paid today.”

That is process hacking.

For more guidance on what to do and how to respond to an email attack the FBI has a few pointers to offer here.


Small companies often have short approval chains.

The owner may directly email the bookkeeper.

The office manager may regularly pay vendors.

Employees may know each other well enough that an urgent request from the boss feels normal.

That trust is valuable inside a small team.

It can also be exploited.

An attacker does not need to fool twenty departments. They may only need to fool one person who can send money.


Strong passwords, MFA, passkeys, and password managers remain essential.

However, this type of fraud can succeed even when the attacker never steals a password.

If the employee believes the request and sends the money voluntarily, identity security alone cannot stop the transaction.

That is why payment controls matter just as much as account security.


Every small business should establish a simple rule:

Large, unusual, or changed payment requests must be verified through a second trusted channel.

That means the employee should not reply to the same email thread and ask, “Is this really you?”

Instead, they should call a known phone number, speak to the owner in person, use a known Teams account, or verify through another established company method.

The second channel should be independent of the message that created the request.


A practical small-business policy could require secondary approval for:

  • New vendors
  • Changed bank account details
  • Large ACH transfers
  • Wire transfers
  • Urgent payments outside normal procedure
  • Invoices that arrive from a new email address
  • Requests that bypass the usual approval process

The dollar threshold will vary by company.

The important part is that employees know the rule before a suspicious request arrives.


Display names are easy to fake.

A message may show the owner’s name while coming from a lookalike address.

Employees should check the full sender address, especially when money or account changes are involved.

Look for:

  • Misspelled domains
  • Extra letters
  • Unexpected free email accounts
  • Recently changed vendor addresses
  • Reply-to addresses that differ from the sender

This does not catch every attack, but it can expose many common ones.


Business procedures are essential, but technical controls still matter.

Small businesses should use:

  • SPF
  • DKIM
  • DMARC
  • MFA
  • Secure email filtering
  • Endpoint protection
  • Managed monitoring

These controls can reduce spoofing, detect suspicious messages, and make account compromise more difficult.

They should support employee verification, not replace it.


  1. Set a payment-verification rule.
  2. Choose a second trusted verification channel.
  3. Define which payments need extra approval.
  4. Train employees not to rely on display names.
  5. Review MFA and email security settings.
  6. Make sure staff know who to call when a request feels unusual.

Did Microsoft prove AI created these phishing emails?

No. Microsoft identified indicators consistent with generative AI use, but that is not the same as proving AI generated every message in the campaign.

Was ServiceNow hacked?

There is no evidence that ServiceNow itself was compromised in this campaign. Attackers used ServiceNow-related branding and invoice themes as part of the social-engineering story.

How much money were attackers requesting?

Microsoft documented ACH payment requests approaching $50,000 in some cases.

What is business email compromise?

Business email compromise, or BEC, is fraud that impersonates a trusted person or organization to convince employees to send money, change payment information, reveal data, or take another harmful action.

Does MFA stop business email compromise?

MFA can reduce account takeover risk, but it cannot stop an employee from voluntarily sending money after believing a fake payment request.

What should we do if money has already been sent?

Contact the bank or payment provider immediately, notify your IT or cybersecurity provider, preserve the email and related evidence, and begin incident-response procedures. Speed matters.


SofTouch Systems Simplifying technology, maximizing results

AI is making business email fraud more convincing, but the defense does not need to be complicated.

A simple verification rule can interrupt the attack before money leaves the account.

SofTouch Systems helps small Texas businesses improve email security, identity protection, employee awareness, and practical IT procedures.

If you are unsure whether your current payment-verification and email-security practices are strong enough, start with a free 15-minute IT security check.

Verify before you pay. Then make sure your employees know exactly how.


Home » AI Fraud » Your Boss Approved This Invoice. Or Did They? AI Is Changing Business Email Fraud

Discover more from SofTouch Systems

Subscribe to get the latest posts sent to your email.

What do y'all think?

Discover more from SofTouch Systems

Subscribe now to keep reading and get access to the full archive.

Continue reading