Microsoft Flags Million-Message BEC Fraud Run

Microsoft said it observed an AI-assisted business email compromise campaign that sent more than a million scam emails between August 3 and 5, using third-party delivery accounts to target enterprise users. The messages impersonated CEOs and other executives and tried to push finance teams toward an ACH payment of nearly $50,000. Microsoft said the emails did not rely on a single lure. They combined a fake invoice, a forwarded thread, vendor branding, and executive-style signatures, so the request looked like an ordinary internal payment approval chain instead of an obvious outside phishing note. That matters for any accounts payable process that treats sender reputation as a proxy for trust. If payment approval happens over email, the exposure sits in the business process itself: layered pretext and trusted delivery can make a fraud request look routine even when the mailbox defenses are working as designed.

Part of the PlainSec briefing for 2026-09-11

Editions

Sources