Treat executive payment requests as identity-verification events

The signal in one glance
What you need to know
- A reported business email compromise campaign used AI-assisted executive impersonation and counterfeit invoices to pressure finance staff into making ACH payments.
- Payment fraud often succeeds at the point where business processes assume that a familiar sender is trustworthy.
- Action: Require a second-channel confirmation for new payment instructions, changed bank details, urgent transfers, and unusual invoice requests; use a known phone number or established collaboration channel.
What happened
A reported business email compromise campaign used AI-assisted executive impersonation and counterfeit invoices to pressure finance staff into making ACH payments. The attackers appear to have focused on a familiar weakness: employees may trust a request because it resembles a leader’s writing style, uses plausible business context, and arrives during a normal payment workflow.