In this article
Microsoft recently documented a single email scam campaign that flooded enterprise inboxes all over North America; over a million emails were sent within three days. They fabricated an entire transaction — fake CEO approval, personalized invoice, manufactured email thread — and aimed it straight at Accounts Payable.
Their goal: convince a real employee to authorize a real payment of nearly US$50,000 to a fake vendor.
It was a human story designed to exploit your approval workflow, not your firewall.
- an attacker impersonates your CEO
- attaches a branded invoice
- includes a fabricated email thread showing prior approval.
The attack succeeds the moment an AP clerk thinks, “This looks normal, the boss already signed off, I’ll process it.”
Handling the technology layer
As your technology partner, we harden your systems. We configure SPF, DKIM and DMARC. We deploy anti-impersonation controls, external sender banners, and post-delivery remediation tools that pull malicious emails out of inboxes after they land. We run phishing simulations and train your staff to recognise suspicious messages.
This is all critical, but in an AI world, it’s just the baseline. In this cyberscam, technology wasn’t the point of failure. No malicious link. It didn’t carry a virus.
Handling the process layer: this workflow will protect against attacks
- Never rely on the contact details on the invoice or in the email. Check them against the company website, watch for contact and domain names with slightly misspelt words.
- Verification of payment changes. Any request to update vendor banking details or initiate a one-off payment above a defined threshold must be confirmed via a pre-established phone number stored in your CMS system, not sent in the email.
- Dual-authorisation for banking. High-value wires should require two separate approvals: one to initiate, one to release. A single user should never be able to complete a transfer alone.
- No email-only financial approvals. Executive sign-off for funds must be logged inside your ERP or procurement system, not buried in an email thread that can be forged in minutes. Even a phone call and zoom meeting can be spoofed.
- AP staff need to know exactly which scenarios require them to stop and verify such as unusual amounts, new vendors, urgent requests, changed account details.
Handling the human layer
Humans are the ultimate firewall, and your staff need to know what to look for. With AI, we can’t rely on bad spelling any more!
- In an email thread, scammers are lazy about emails at the beginning of the thread. Check that the “From” headers have sensible dates and contact names, the same as the later forwarded emails. AI can get confused about the to-and-fro of a human conversation.
- Suspicious language used in the spoofed thread such as “no need to copy me”.
- Display name not matching sender address,
- Subjects using financial lure keywords like ‘due bill’, ‘Urgent ACH Payment’ etc.
- In real email threads, the previous threads are normally tabbed or otherwise visually grouped, while the previous threads in this example were left aligned.
- The “CEO” asks the employee to bypass a normal process.
- What for the wrong domain name in a replay to – there could be a single letter difference.
Where Corporate IT is different
Our approach integrates all three layers:
- Technology: Microsoft Defender hardening, email authentication, anti-impersonation, post-delivery purge, phishing simulations…
- Process: reminding you to review your financial authorization workflows, so that a convincing email can’t bypass your controls.
- Human behaviour: training and education that focuses on social engineering tactics targeting your finance and operations teams.
The bottom line
If someone impersonated your CEO tomorrow and instructed Accounts Payable to wire $50,000 to a new account, what would actually stop that payment? Would your staff question the CEO. What if he phoned them. What if it was a live zoom call? AI is capable of impersonating individuals including voices and how they look.
The fix isn’t just another security tool. It’s making sure your technology, your processes, and your people are working as a single system.