Azure

AI-powered BEC scams use deepfake execs and fake invoices to steal ACH payments

Microsoft details a new AI-assisted business email compromise campaign that impersonates executives and forges invoices to trick finance teams into sending fraudulent ACH payments.

E

Everything Cloud

Everything Cloud

AI-powered BEC scams use deepfake execs and fake invoices to steal ACH payments

Attackers are using generative AI to create convincing deepfake audio and video of executives, paired with forged invoices, to manipulate finance teams into authorizing unauthorized ACH transfers. This emerging threat combines social engineering with synthetic media to bypass traditional email security controls. Organizations must now defend against AI-enhanced impersonation that mimics trusted voices and documents with high fidelity.

Microsoft

How the AI-assisted BEC attack works

The campaign begins with attackers gathering public information about target executives from sources like corporate websites, press releases, and social media profiles. Using this data, they train or prompt generative AI models to produce realistic audio or video deepfakes that mimic the executive’s voice, speech patterns, and mannerisms. These synthetic media clips are then used in phone calls or voicemails to urgently request wire transfers, often citing confidential acquisitions or time-sensitive vendor payments.

Simultaneously, attackers forge invoices that appear to come from legitimate vendors, complete with accurate logos, formatting, and payment details that match past legitimate transactions. These fake invoices are delivered via compromised or spoofed email accounts, often using lookalike domains or compromised third-party vendor accounts to evade detection. The invoices typically request ACH payments to accounts controlled by the attackers.

Finance teams, believing they are responding to a legitimate executive request backed by authentic documentation, process the payments without triggering standard approval workflows. The urgency and perceived authority of the deepfake communication override typical verification steps, such as callback confirmations or dual approvals. By the time the fraud is detected, funds have often been moved through multiple layers to obscure recovery.

Why traditional defenses fail against AI-enhanced fraud

Standard email security tools focus on detecting malicious links, attachments, or known spoofing indicators, but they are ineffective against AI-generated content that lacks malware or malicious URLs. Deepfake audio and video leave no digital artifacts that conventional scanners can flag, especially when delivered via voice calls or embedded in legitimate-seeming email threads. Similarly, forged invoices often pass visual inspection because they replicate real templates with high accuracy.

Attackers exploit the trust finance teams place in executive communications and established vendor relationships. By using AI to replicate nuanced vocal tones and contextual phrasing—such as referencing recent company events or internal jargon—they reduce skepticism and increase compliance. This psychological manipulation is harder to defend against than technical threats because it targets human judgment rather than system vulnerabilities.

Furthermore, the speed and scale of AI-generated content allow attackers to launch highly personalized campaigns at volume, increasing the likelihood of success. Unlike older BEC tactics that relied on generic templates, this approach adapts dynamically to each target, making pattern-based detection less effective. The result is a more convincing and scalable fraud vector that evades both automated and manual review processes.

Recommended defenses for finance and security teams

Organizations should implement strict verification protocols for any payment request involving executive urgency or changes to vendor payment details. This includes requiring out-of-band confirmation—such as a known phone call to the executive’s verified line or a separate message via a trusted channel like Teams—before processing any ACH change, regardless of how authentic the request appears.

Finance teams should adopt invoice validation tools that check for anomalies in vendor metadata, bank account history, and payment patterns, even when documents appear visually legitimate. Integrating these checks into ERP or AP systems can flag mismatches in routing numbers, account ages, or geographic inconsistencies that may indicate fraud, even if the invoice looks correct.

Security teams must expand user awareness training to include AI-generated media threats, teaching staff to recognize signs of deepfakes such as unnatural blinking, audio glitches, or mismatched lip-sync in video. Simulated phishing exercises should now include voice and video lures to build resilience. Additionally, investing in AI-driven detection tools that analyze vocal or visual inconsistencies in media can help identify synthetic content before it leads to financial loss.

What to do next

To mitigate this evolving threat, finance and security leaders should urgently review payment approval workflows, enforce out-of-band verification for all executive-initiated fund transfers, and deploy AI-aware detection tools for both communications and invoices. Proactive validation and human vigilance remain the strongest defenses against AI-powered impersonation fraud.

Source: Protecting organizations from AI-assisted executive impersonation and invoice fraud (Azure).

Share:TwitterLinkedIn

Related Articles