Microsoft Warns of AI-Assisted Invoice Fraud and Passkey-Based Cloud Attacks
Microsoft has revealed details of two cybercrime campaigns targeting organizations through financial fraud and cloud account compromise. One campaign used AI-assisted executive impersonation to send more than one million fraudulent invoice emails, while the other used passkey-themed social engineering to gain access to Microsoft cloud environments.
AI-Assisted Executive Impersonation Targets Finance Teams
Between August 3 and 5, 2026, threat actors sent more than one million scam emails while impersonating company CEOs and senior executives.
The attackers attempted to trick accounts payable teams into making Automated Clearing House (ACH) payments for a fake annual ServiceNow subscription.
The campaign mainly targeted U.S. organizations in the following sectors:
- IT services
- Consumer goods
- Real estate
- Discrete manufacturing
Microsoft said the attackers used generative AI to create convincing email templates and tailor messages to individual recipients.
The fraud campaign followed several steps:
- Registering domains that impersonated trusted companies or brands.
- Sending payment requests through trusted email delivery infrastructure.
- Creating fake invoices and supporting email conversations.
- Adding fabricated approval messages to make the payment appear legitimate.
- Using the names and email addresses of CEOs, CFOs, and other senior executives in email signatures.
Two domains associated with the campaign included:
service-nowinc[.]comdomainlify[.]net
Unlike traditional invoice scams, the attackers combined executive impersonation, vendor branding, fake invoices, and forged email threads to make the requests appear more credible.
Passkey-Themed Social Engineering Leads to Cloud Compromise
Microsoft also reported a separate campaign that has been active since May 2026. The attacks targeted cloud identities and involved suspicious sign-ins, unauthorized authentication methods, Microsoft Graph activity, SharePoint and OneDrive downloads, and mailbox collection.
The campaign commonly began with a phone call or message to an employee's personal device. The attacker claimed to be from the company's IT help desk and told the employee to update their passkey, multi-factor authentication, or single sign-on settings.
The victim was then redirected through SMS messages to a fake Microsoft sign-in page. The attackers used adversary-in-the-middle phishing or device-code authentication techniques to capture access or persuade the victim to approve authentication on the attacker's behalf.
Attackers Conduct Extensive Pre-Attack Research
Microsoft said the threat actors appeared to research employees and company structures using publicly available information from social networks and professional profiling platforms.
In some cases, attackers used already compromised accounts to send similar passkey-themed messages through Microsoft Teams.
The attackers also registered domains related to passkeys, SSO enrollment, account activation, and identity verification. These domains sometimes used the target company's name as a subdomain.
Examples included:
passkeyhelpdesk[.]comsecure-passkey[.]comsetupmypasskey[.]comadd-passkey[.]comintegratedsso[.]comoktasession[.]comsyncmykey[.]comportalsetuphub[.]com
The activity shares similarities with cybercrime groups tracked as Cordial Spider, O-UNC-045, PREY-0058, and UNC6671. Microsoft has also associated parts of the activity with threat actors tracked as Storm-3121 and Storm-3032.
Attackers Add Their Own MFA Methods
In one attack pattern, threat actors used compromised credentials to register their own phone number, authenticator application, or software-based one-time password token.
This allowed them to maintain access even after the initial compromise. If existing sessions or credentials remained valid, the attackers could continue accessing the victim's account without further interaction from the employee.
After gaining access, the attackers could:
- Use Microsoft Graph API to identify users, groups, permissions, resources, and sensitive content.
- Review privileged roles and high-value accounts for possible escalation.
- Examine mailbox messages, folders, and attachment metadata.
- Download large volumes of files from SharePoint Online and OneDrive.
- Access Microsoft Exchange Online in some cases.
- Exfiltrate data over several hours or days.
- Rotate IP addresses and infrastructure to make detection more difficult.
Microsoft also observed a device-code phishing technique that allowed attackers to take control of accounts without directly stealing passwords or browser cookies, effectively bypassing traditional MFA protections.
Microsoft Recommends Holistic Detection
Microsoft warned that malicious Microsoft Graph activity may not appear suspicious when individual API requests are examined separately.
Organizations should instead investigate the complete sequence of events, including:
- Suspicious sign-ins.
- Unexpected authentication method changes.
- New phone numbers or authenticator registrations.
- Unusual Graph API reconnaissance.
- High-volume SharePoint, OneDrive, or mailbox access.
- Unusual data downloads and exfiltration.
- Changes in attacker IP addresses and infrastructure.
The campaigns highlight the growing use of AI-assisted fraud, identity-focused social engineering, and MFA persistence techniques against enterprise environments.