Back to BlogEmail Security Insights

Would DMARC stop a fake CEO invoice? Inside the million-email ACH scam

StopSpoofingMe TeamPublished 7 min read

In early August 2026, attackers sent more than a million emails that used CEOs' names to "approve" a fake ServiceNow invoice and ask accounts payable for an ACH payment of nearly $50,000. Microsoft disclosed the campaign on September 10. DMARC can't catch a borrowed display name, so confirm every payment request by phone.

Key takeaways

  • Between August 3 and 5, Microsoft detected a campaign of more than a million emails aimed at enterprise users, 87.7% of them in the United States.
  • The CEO's name appeared in the sender display name, the reply-to display name and the signature, above a fabricated "forwarded" invoice and email thread.
  • A lookalike domain, service-nowinc[.]com, was registered on July 31. Microsoft found no evidence that ServiceNow or the other impersonated organizations were compromised.
  • DMARC checks the domain in the From address, not the name shown beside it. An accounts-payable callback rule is what stops this scam.

What happened?

In early August, attackers ran a large invoice-fraud campaign against finance teams. Microsoft disclosed it on September 10, 2026. According to Microsoft:

  • Scale and targets. Between August 3 and 5, Microsoft detected more than a million emails aimed at enterprise users. The attackers sent them through multiple third-party email service accounts. 87.7% went to users in the United States. Targeted industries included IT services and business advisory, consumer goods and others.
  • The ask. The attackers impersonated executives (such as a CEO, CFO or President) of multiple targeted companies and asked accounts-payable staff at those same companies to process an ACH payment of nearly $50,000. The email body gave a simple, direct "approval" of the "invoice below".
  • The props. Below the fake executive's signature sat a "forwarded", professional-looking but fabricated "ServiceNow Platform — Annual Subscription" invoice with ServiceNow branding. Its "BILLED TO" section was personalized with the recipient company's name and executive. The invoice asked for payment by bank transfer to accounts controlled by the attacker. Below that came a fake "forwarded" conversation between the company's executive and a spoofed ServiceNow President.
  • The domains. The attacker registered the lookalike domain service-nowinc[.]com on July 31. It was used for the fake ServiceNow President's address and as a contact address on the invoice. A second domain registered the same day, domainlify[.]net, was used as the Reply-To address.
  • No breach at ServiceNow. Microsoft says it found no evidence that the legitimate organizations referenced in the lures, including ServiceNow, were compromised or involved.

Did AI write these emails?

Maybe, in part. Microsoft observed "several indicators consistent with AI-assisted template development", including extensive HTML comments, structured section labels and highly uniform templates. It added that while "these indicators suggest generative AI involvement, they do not independently establish the extent to which AI generated campaign content." Either way, the playbook is classic business email compromise (BEC).

The typo in the scam

For all the polish, Microsoft's list of warning signs includes subject lines using financial lure keywords such as "due bill" and "ACH Parment". Yes, the scammers misspelled "payment" in a payment scam.

Why does this matter for your business?

According to Microsoft, the campaign relied on fraudulent domains and content designed to mimic trusted brands and people. It counted on readers trusting names.

Your DMARC record doesn't cover display names. DMARC lets receivers check whether mail really comes from the domain in the From address. According to Microsoft, the CEO's name was placed in the display name, the reply-to display name and the signature. The sender addresses Microsoft published are on a mix of unrelated domains. When the From address is on someone else's domain, it's that domain's DMARC policy that gets checked, not yours. (Microsoft didn't publish SPF, DKIM or DMARC results for these messages, so we can't say whether they passed their own checks.)

The vendor's DMARC doesn't cover lookalikes either. service-nowinc[.]com is a different domain from ServiceNow's real one, so ServiceNow's DMARC never applies to it. Here it appeared as text inside the fake thread and invoice, which no authentication check vouches for. And when attackers do send from a lookalike, Microsoft's documentation notes it can pass SPF, DKIM and DMARC if the attacker publishes valid DNS records.

The story is built to skip your checks. An executive "approval", a detailed invoice and a fake vendor thread all suggest the work is already done. The defense is a process that runs every time. Impersonation domains aimed at a trusted-partner relationship also drove the $7.5M charity fraud case we covered recently.

Red flags your AP team can check

Microsoft listed signs that the email and its "forwarded" thread were fake. Turn them into checks:

Warning sign in Microsoft's write-up What to check
Display name doesn't match the sender address Expand the sender. Is the address on your company's own domain?
A Reply-To address on another domain Look at where a reply would actually go before you answer
"Forwarded" messages missing the usual header details Real forwards show who sent what, when and to whom
Earlier messages left-aligned instead of grouped or indented like a real thread Does the thread look like one your email app produced?
Language such as "no need to copy me" An executive asking to stay out of the loop on a payment
Subject keywords such as "due bill" or "ACH Parment" Urgency, payment words and misspellings in the subject
The fake thread's CEO asks not to be copied, yet his latest message approves the invoice from his address Does the story contradict itself?

What should you do now?

  1. Adopt a callback rule for payments. Any new payee, changed bank details or "approved" invoice you weren't expecting gets confirmed by phone, using a number from your vendor file or company directory. Never use contact details from the email.
  2. Match every invoice to a purchase. Do you actually use this service? Is the vendor already in your accounting system, with a purchase order or contract? An invoice for something nobody ordered is a red flag on its own.
  3. Require two approvals for ACH and wires above a set amount, even when "the CEO" is asking.
  4. Have executives say it out loud: "I will never approve a payment by email alone." That gives staff permission to slow down.
  5. Make names less trustworthy in the inbox. Microsoft 365's first contact safety tip warns people when they don't often get email from a sender, and Microsoft recommends turning it on. Defender for Office 365 adds impersonation protection that you can point at your executives and your key vendors' domains; see what's included in Defender for Office 365 Plan 1.
  6. Lock down your own domain. This campaign used other people's domains, but without an enforced DMARC policy, receiving servers aren't asked to block mail that forges your real address in the From line. Check your SPF, DKIM and DMARC setup with our free domain scanner and move toward p=reject.

For help with email authentication or payment controls, call us at (818) 574-8240.

Frequently asked questions

Would DMARC have stopped this scam?

Your own DMARC policy wouldn't have. DMARC protects the exact domain in the From address. In this campaign, the CEO's name was used as a display name on unrelated sender addresses, and the vendor was impersonated with a lookalike domain. Neither is something your DMARC policy checks. Enforcing DMARC is still worth it: it tells receiving servers to quarantine or reject mail that forges your real domain.

What is display-name impersonation?

Every email has a display name (the friendly name you see) and an address. The display name can be set to anything, so a scammer can show your CEO's name while sending from an unrelated address. Before acting on any request involving money, tap or hover over the sender's name to see the real address behind it.

Was ServiceNow hacked?

According to Microsoft, no. It found no evidence that ServiceNow or the other legitimate organizations referenced in the lures were compromised or involved. The attackers built a fake invoice with ServiceNow branding and used a lookalike domain, service-nowinc[.]com, registered on July 31. Any brand your company pays could be imitated the same way.

What should we do if we already paid a fake invoice?

Call your bank immediately and ask it to recall or freeze the ACH payment, because the first hours matter. Report the fraud to the FBI's Internet Crime Complaint Center (IC3) and to local law enforcement. Keep the original email with full headers, and warn your AP team about follow-up attempts.

Sources

  1. Microsoft Security Blog — Protecting organizations from AI-assisted executive impersonation and invoice fraud (September 10, 2026)
  2. Microsoft Learn — Anti-phishing policies in cloud organizations (reference documentation, undated)
  3. U.S. Attorney's Office, District of Maryland — press release on Olusegun Adejorin's conviction by a federal jury (December 2025)

Editor's note: This article was researched and written with AI assistance. Every factual claim was checked against the sources listed above; see our fact-check process for details.

Related Topics

CEO impersonation email scamfake invoice ACH scamdisplay name spoofingaccounts payable fraud preventionlookalike domain invoice frauddoes DMARC stop CEO fraudbusiness email compromise 2026

Ready to Secure Your Email?

Check your domain's email security status with our free scanner, or get professional help setting up DMARC, SPF, and DKIM.