Microsoft Tracks AI-Assisted Phishing Campaign Sending 1 Million Emails in 3 Days

This digest was compiled by AI from multiple sources — links to the originals are below.
Microsoft researchers tracked a phishing campaign last month in which an unattributed threat actor sent more than one million emails in three days. The emails targeted accounts payable departments and were lightly personalized with the real names of executive leadership, likely with AI assistance. The campaign impersonated ServiceNow and used forged email threads to add credibility.
Key Facts
- Microsoft researchers tracked a phishing campaign in which an unattributed threat actor sent over one million emails in three days.
- The emails impersonated ServiceNow and claimed victims owed just under $50,000 for an annual subscription.
- Attackers identified CEOs, CFOs, and presidents at victim organizations and inserted their names into email signatures.
- Merium Khalid, director of AI and automation at Barracuda Networks, said AI can gather victim organization information in minutes.
Campaign Mechanics
The phishing emails claimed victims' companies owed just under $50,000 to ServiceNow for an annual subscription. Attached invoices included credible line items and non-round dollar amounts, with visual branding matching the impersonated company. Attackers wrapped each email and invoice in a forged email thread between an executive at the victim's company and the president of ServiceNow. The forged thread showed the executive asking ServiceNow to forward the invoice directly to the victim in the finance department.
AI Personalization
Microsoft found telltale signs that the threat actor used AI to personalize the email template for specific victims. Merium Khalid of Barracuda Networks said AI can rapidly process public information such as company websites, executive details, and press releases. Khalid added that attackers can build multiple AI-driven processes for information gathering, personalized content generation, and template creation.