Sep 20 / Admin

New Scam Alert: Microsoft Warns AI Campaign Targeting Finance Teams

Intelligent CISO reported:  

Microsoft has warned organisations about a large-scale business email compromise campaign in which attackers impersonated company executives and attempted to convince finance teams to make fraudulent payments of almost US$50,000.

Between August 3 and 5, Microsoft detected more than one million emails targeting enterprise users, with 87.7% of the campaign directed at users in the US.

Rather than relying on a single social engineering lure, the campaign combined executive impersonation with vendor branding, fabricated invoices and fake forwarded email conversations to create a more convincing narrative.

 In examples analysed by Microsoft, attackers impersonated ServiceNow and included a professional-looking fraudulent invoice for an annual platform subscription. The invoices contained branding, payment information and personalised details relating to the targeted company and executive.

Find the original article here.
 
Key Takeaways:  Don't change banking based on an invoice.  Have a controlled process to change remittance details. Review the email to see if there are any red flags.  Use an AI Tool to help.  Check out the training session to see how to use Microsoft Copilot to spot red flags in an email or your inbox. 

Enroll in Training Sessions:  Last Thursday of Every Month is Training on Frauds and New Scam Alerts and How to Combat
Click Image to Enlarge
Created with