A staggering one million emails, each carefully crafted with the victim’s name and tailored to their specific role within a company, were sent in just three days by a cunning threat actor using artificial intelligence (AI) to fuel its phishing campaign. This unprecedented volume of personalized emails was able to evade detection and convince targets that they owed money to a legitimate enterprise cloud services provider, ServiceNow.
The attackers’ strategy involved identifying CEOs, CFOs, and presidents at victim organizations and incorporating their names into the email signatures. This level of personalization would have been impossible without AI’s ability to rapidly process publicly available information about a company and its executives. “Gathering information about a victim organization can now be a matter of minutes,” says Merium Khalid, director of AI and automation for the Office of the CTO at Barracuda Networks. “AI can rapidly process publicly available information on the internet about an organization — such as company websites, executive information, employee roles, press releases, and other public sources — and use that context to help construct more convincing impersonation emails.”
The phishing emails themselves were convincing, with detailed invoices attached featuring credible line items and dollar amounts. The attackers even went so far as to create a brief email “thread” between an executive at the victim’s company and the president of ServiceNow, making it seem like the request for payment was legitimate. This level of sophistication would have been difficult to achieve without AI’s assistance.
The campaign’s targets spanned various industries, with IT, consumer goods, and real estate companies being the most common. A staggering 87.7% of the targeted organizations resided in the US. Microsoft researchers were able to track the phishing campaign and identified telltale signs that the threat actor used AI to assist in personalizing its email template.
The implications of this attack are sobering, as experts emphasize that AI’s greatest proven threat so far is its ability to enhance old-fashioned kinds of cyberattacks. “New AI-native threats like adversarial agents and prompt injection will create new risks, but phishing, impersonation, and fraud already have proven paths to success,” says Joshua Bartolomie, vice president and global head of threat intelligence at Doppel. “AI makes those attacks faster, cheaper, more personalized, and easier to scale.”
As we navigate this new era of AI-fueled cyber threats, it’s essential for organizations to remain vigilant and take proactive measures to protect themselves from such attacks. This means implementing robust email security protocols, training employees on phishing tactics, and staying informed about the latest threat trends. By being aware of these emerging risks and taking steps to mitigate them, we can reduce the impact of AI-driven cyberattacks and keep our digital assets secure.
Source: Dark Reading — 2026-09-11