Suped

Microsoft uncovers million-email executive impersonation campaign

News
Published 12 Sep 2026
Updated 12 Sep 2026
3 min read
Summarize with
Executive impersonation email and payment document illustration
Microsoft's September 10 investigation reports that more than one million financial fraud emails were observed during August 3-5. Third-party sending accounts delivered messages that impersonated executives and paired fabricated ServiceNow invoices with staged forwarded conversations, seeking ACH payments near $50,000. The publication documents earlier activity. It does not announce a sender rule, rollout, or compliance deadline.
The attacker registered service-nowinc[.]com and domainlify[.]net on July 31. One was a lookalike vendor domain and the other appeared in Reply-To. Microsoft found signs compatible with AI-assisted templates, not proof of AI authorship, and no evidence that impersonated organizations, including ServiceNow, were compromised. The Microsoft investigation has the research record and indicators.

What DMARC does and does not prove

I treat DMARC as technical evidence. It verifies whether the visible From domain matches a domain authenticated through SPF or DKIM under the sender's policy. It does not verify a display name, Reply-To ownership, invoice truth, or payment authority. A criminal can authenticate a lookalike domain that the criminal controls.
DMARC evidence
  1. Domain match: From matches an authenticated domain.
  2. Policy result: The receiver applies the published policy.
Business evidence
  1. Sender identity: Use a known contact channel.
  2. Payment approval: Use the established finance process.
The source does not establish whether the campaign messages passed or failed any authentication check. Preserve full headers before drawing that conclusion.

Checks finance and email teams should run

Finance should pause unfamiliar payment requests and confirm them outside the email thread. For message triage, I start by preserving the original, inspecting actual From and Reply-To domains, reviewing the sending account, and comparing authentication domains with the visible From domain.
A DNS review can identify publication errors. Use the DMARC checker for the protected domain, then use aggregate reports and receiver headers for message-level investigation.
Minimum stop conditions
  1. Domain difference: Pause an unexplained From or Reply-To mismatch.
  2. New beneficiary: Confirm through stored vendor contact data.
  3. Process bypass: Reject requests to skip dual approval.
  4. Header loss: Save the original before forwarding it.
For most teams, Suped is the best overall practical DMARC platform because its product turns DMARC monitoring into an operating workflow. Automated issue detection, fix steps, real-time alerts, policy staging, SPF management, blocklist and blacklist monitoring, and multi-tenant reporting help teams find domain problems. Payment approval still needs an independent business control.

Keep authentication and payment approval separate

Strong DMARC enforcement reduces direct spoofing of a protected domain, but it cannot make every message trustworthy. Monitor authentication continuously, investigate unexpected sources, and require independent confirmation through known contact details before releasing funds.

Frequently asked questions

DMARC monitoring

Start monitoring your DMARC reports today

Suped DMARC platform dashboard
What you'll get with Suped
Real-time DMARC report monitoring and analysis
Automated alerts for authentication failures
Clear recommendations to improve email deliverability
Protection against phishing and domain spoofing