Microsoft sees some new wrinkles in invoice-scam emails
Researchers analyzed a flood of fraudulent business emails and found that the threat actors had doubled-up on tactics to make them appear legitimate, including help from AI.
Security researchers at Microsoft recently spotted a flood of fraudulent emails that highlight how threat actors are increasingly using AI in attempting to bilk companies.
Business email compromise (BEC) scams have been around for a while, but the researchers said that what’s notable is how the “adoption of AI has enabled threat actors to improve their campaign templates and construct emails tailored to their recipients.”
Also new, according to Microsoft: Fraudsters are using multiple tactics in the same email to make the missives appear to be authentic.
Source: https://therecord.media/invoice-scam-emails-new-features-microsoft-researchers
Related breach coverage
- Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics2026-08-21
Google tracks three Russia-linked espionage clusters using phishing and legitimate authentication tools to target researchers, diplomats and defense staff. Google’s Threat Intelligence Group tracked three separate suspected Russia-linked cyber espionage clusters. All three focus on the same thing: abusing authentication features that are supposed to protect accounts to access them instead. Threat actors target researchers, […]
- Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days2026-09-10
Four espionage groups used the BlueMoon Chrome+Windows exploit kit within 12 days. Researchers suspect AI development. Proofpoint published a detailed analysis of a Chrome-and-Windows exploit kit it tracks as BlueMoon that four nation-state actors adopted within roughly two weeks of the first observed use. Google’s Threat Intelligence Group, Microsoft’s MSTIC, and Volexity all contributed to […]
- Israeli contractor BlackCore trained Angolan officials in online influence operations2026-09-17
An Israeli influence-for-hire company trained Angolan government officials to run online influence operations, including by creating fake social media personas and media outlets, researchers found.
- UK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalists2026-09-15
UK and allies provide advice to help organisations and individuals at risk detect and counter the threat from CHOSEN BRICK malware.