Overview
Between August 3–5, 2026, attackers launched a massive business email compromise (BEC) campaign, sending over 1 million spoofed emails to employees—primarily in the United States (87.7% of recipients). The goal: trick accounts‑payable staff into authorizing ACH transfers of nearly $50,000 to attacker‑controlled bank accounts.
Attack Chain
- CEO impersonation: Emails spoofed senior leaders (CEOs, CFOs, presidents) in sender display names, reply‑to fields, and signatures.
- Fake invoices: Forwarded subscription invoices carried ServiceNow branding, invoice numbers, dates, and itemized charges.
- Personalization: Invoices tailored with recipient company names and executive identities.
- Payment instructions: Directed staff to transfer funds to attacker bank accounts.
- AI‑assisted templates: Structured HTML, consistent formatting, and comments suggested generative‑AI support in crafting lures.
Warning Signs
- Display names mismatched sender addresses.
- Subjects used odd phrases like “due bill” and “ACH Parment.”
- Forwarded messages lacked normal headers and alignment.
- Domains registered to mimic vendors (e.g., service‑nowinc[.]com).
Indicators of Compromise (IoCs)
| Type | Indicator | Description |
|---|---|---|
| Domain | service‑nowinc[.]com | Impersonates ServiceNow |
| gomez@service‑nowinc[.]com | Linked to attacker bank account | |
| notifications@uinsure[.]co[.]uk | Campaign sender | |
| info@tivityhealth[.]com | Campaign sender | |
| noreply@mctci[.]com | Campaign sender | |
| Domain | domainlify[.]net | Reply‑To domain used in fraud |
(Note: Domains intentionally defanged to prevent accidental resolution.)
Defensive Guidance
Organizations should:
- Verify payment requests via phone or trusted contacts, not email replies.
- Enable SPF, DKIM, DMARC to block spoofed messages.
- Train finance teams to inspect sender addresses, headers, and invoice formatting.
- Quarantine suspicious emails and enable post‑delivery removal where possible.
- Monitor domains and block lookalike registrations.
- Provide reporting channels so finance staff can escalate suspicious requests quickly.
Expert in the Cloud Insight
This campaign illustrates how BEC attacks exploit trust, routine processes, and urgency rather than malware. By impersonating executives and vendors, attackers bypass technical defenses and target human judgment. The lesson is clear: verification must be a process, not a judgment call—because one convincing email can trigger a $50,000 loss.
Leave a Reply