Hackers Impersonate CEOs

Overview

Between August 3–5, 2026, attackers launched a massive business email compromise (BEC) campaign, sending over 1 million spoofed emails to employees—primarily in the United States (87.7% of recipients). The goal: trick accounts‑payable staff into authorizing ACH transfers of nearly $50,000 to attacker‑controlled bank accounts.

Attack Chain

  • CEO impersonation: Emails spoofed senior leaders (CEOs, CFOs, presidents) in sender display names, reply‑to fields, and signatures.
  • Fake invoices: Forwarded subscription invoices carried ServiceNow branding, invoice numbers, dates, and itemized charges.
  • Personalization: Invoices tailored with recipient company names and executive identities.
  • Payment instructions: Directed staff to transfer funds to attacker bank accounts.
  • AI‑assisted templates: Structured HTML, consistent formatting, and comments suggested generative‑AI support in crafting lures.

Warning Signs

  • Display names mismatched sender addresses.
  • Subjects used odd phrases like “due bill” and “ACH Parment.”
  • Forwarded messages lacked normal headers and alignment.
  • Domains registered to mimic vendors (e.g., service‑nowinc[.]com).

Indicators of Compromise (IoCs)

TypeIndicatorDescription
Domainservice‑nowinc[.]comImpersonates ServiceNow
Emailgomez@service‑nowinc[.]comLinked to attacker bank account
Emailnotifications@uinsure[.]co[.]ukCampaign sender
Emailinfo@tivityhealth[.]comCampaign sender
Emailnoreply@mctci[.]comCampaign sender
Domaindomainlify[.]netReply‑To domain used in fraud

(Note: Domains intentionally defanged to prevent accidental resolution.)

Defensive Guidance

Organizations should:

  • Verify payment requests via phone or trusted contacts, not email replies.
  • Enable SPF, DKIM, DMARC to block spoofed messages.
  • Train finance teams to inspect sender addresses, headers, and invoice formatting.
  • Quarantine suspicious emails and enable post‑delivery removal where possible.
  • Monitor domains and block lookalike registrations.
  • Provide reporting channels so finance staff can escalate suspicious requests quickly.

Expert in the Cloud Insight

This campaign illustrates how BEC attacks exploit trust, routine processes, and urgency rather than malware. By impersonating executives and vendors, attackers bypass technical defenses and target human judgment. The lesson is clear: verification must be a process, not a judgment call—because one convincing email can trigger a $50,000 loss.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.