Skip to content
Reporting on the technology of the open webThe Allow Copy tool

—Gaming Tech

Researchers Warn: AI-Powered Phishing Kits Now Auto-Generate Convincing Payment Invoices

29 September 2026

Researchers are sounding the alarm over AI-powered phishing kits that have rapidly evolved to automatically generate highly convincing payment invoices and fraudulent payment requests. The escalating sophistication of these tools poses a heightened risk to finance teams, who may now find it even harder to spot realistic-looking invoice fraud.

Late in September, Microsoft published details of a substantial phishing campaign that targeted enterprise users, with more than 1,000,000 emails sent between August 3 and 5 alone. Of those, a striking 87.7% were aimed at US recipients, according to Microsoft's blog.

Drained by Looks-Like-Legit Emails

In that wave, attackers impersonated CEOs and tried to get accounts payable teams to process fraudulent ACH payments of nearly $50,000. Those emails included fabricated invoices for a "ServiceNow Platform—Annual Subscription" that, dismayingly, featured ServiceNow branding, logos, invoice numbers, dates, currency, amounts due, payment methods, and detailed line items.

Microsoft found that the campaign used third-party email delivery infrastructure and impersonation domains in an effort to make the messages appear legitimate. Additionally, researchers spotted indicators consistent with AI-assisted template development, such as extensive HTML comments, structured section labeling, and highly uniform template construction.

This is part of a disturbing trend. Eye Security delved into two AI-powered phishing kits that analyze harvested mailboxes to map an organization’s payment flows, invoices, and outstanding balances. The structured AI output includes roles like payment scenarios, invoices, and financial summaries—all tailored to job-specific lures.

Barracuda also rattled off a list of generative AI techniques attackers are using to produce highly convincing overdue-invoice emails and payment requests to match the tone, style, and branding of the legitimate services. Moreover, a growing number of invoice scams are embedding QR codes in emails to nudge unwary victims from supposedly secure desktop environments to less-defended mobile devices, Barracuda reported.

One Part of Animal Eco-System

AI isn't the only new tool in the criminal arsenal.

Texting and fake revival of leads are also exploding: Barracuda's threat-spotting blog says fake text-based ride-share, emergency, or delivery interactions have sprouted in the past year and uses generative AI to impersonate services.

Additionally, the CISO of Eye Security says use of AI-driven tools by cybercriminals has accelerated, and we've seen more commoditized phishing-as-a-service offerings that include convincing AI content.

End-to-End Fraud Scams

While AI may grab headlines, an AI-assisted cyberattack often combines many forms of deception.

Many phishing kits use AI to generate role-specific lures involving invoices, requests for proposals, or payment-related documents. For example, an attacker could write a script that generated convincing emails in the expected tone of a known legitimate supplier, sent it from a real executive’s email address, and included a fake PDF invoice with all the right logos and line items.

On delivery, the kit might also automatically provide an alternate permissions document that would, when accepted, install malware or ransomware.

Defending Your Org

Both Microsoft and Barracuda urge defenders to layer multiple defenses, as even the most sophisticated email filtering won't spot all of these attacks. Authentication, including DKIM signatures, and mail-flow controls—including ones that monitor unusual volumes of invoice-type emails—are recommended. Dedicated AI detection for phishing is also crucial.