\n\n

DarkReading.com reported that “Artificial intelligence (AI) is enabling threat actors to send unholy volumes of fraudulent emails, personalized to a degree that mass emailers of old couldn’t have touched.”  The September 11, 2026 article entitled “Threat Actor Generates 1M Personalized Fraud Emails in 3 Days” (https://www.darkreading.com/cyberattacks-data-breaches/1m-personalized-fraud-emails-3-days) included these comments:

Last month, Microsoft researchers tracked a phishing campaign in which an unattributed threat actor sent out more than one million emails in just three days. Despite the volume of content they had to juggle, the threat actor managed to specifically target relevant accounts payable departments and lightly personalize each message with the real names of targeted employees’ executive leadership, most likely through serious assistance from AI. A few other bells and whistles, too, made the emails much more convincing than your average Automated Clearing House (ACH) fraud scam.

The basic premise of the emails was that victims’ companies owed just shy of $50,000 to the enterprise cloud services company ServiceNow for an annual subscription. Attached invoices were detailed — with credible line items and dollar amounts that didn’t add up to round numbers — and featured visual elements and branding true to the impersonated company.

In a clever little twist, the attacker wrapped each phishing email and invoice in a forged email “thread.” They created a brief back-and-forth conversation, made to seem like it occurred before the victim received the email, between an executive at a victim’s company and the president of ServiceNow. The executive asked their colleague at ServiceNow to forward the invoice directly to the victim in their finance department.

Anyone surprised?

https://www.vogelitlaw.com/blog/thanks-to-ai-more-than-1-million-phishing-emails-were-created-in-3-days