Restricted analysis, made public daily.
Declassified under standing order Edition No. 075 Wednesday, September 16, 2026

The Names Were Real.
The Approval Was Fabricated.

Between August 3rd and 5th, 2026, Microsoft’s security researchers detected a campaign of more than one million emails impersonating real company executives and the real vendor ServiceNow, seeking ACH payments of nearly $50,000. The names were genuine. The approval history presented in the requests was fabricated. By Microsoft’s own account, the forgery still showed.

The campaign paired two real authorities in the same lure: a recipient company’s chief executive, chief financial officer, or president, and the software vendor ServiceNow — sent more than one million times between August 3rd and 5th, 2026, 87.7 percent of it addressed to recipients in the United States, per Microsoft’s security research team. The email carried an invoice. The invoice carried an ACH request for nearly $50,000. The company, the executive, and the vendor were real. The conversation that supposedly authorized the payment was not.

The infrastructure behind the lure was built with the same discipline as the message itself. Microsoft traced the campaign to a lookalike domain, service-nowinc[.]com, registered three days before the campaign began — a second domain, domainlify[.]net, was registered the same day and used as the lure’s reply-to address. Neither belongs to ServiceNow — both existed to make a fabricated conversation look like it was coming from somewhere real.

What gave the lure its structure wasn’t a flawless forgery. It was a fabricated approval history. The messages were built around what looked like an existing conversation — a forwarded thread, already in motion, in which the invoice had apparently already been discussed. Microsoft’s own analysis found the seams. Missing forwarding headers. A display name that didn’t match the sender address. Phrasing a careful reader could flag. A fake thread running left-aligned, not tabbed and grouped the way a real forwarded conversation is. Several inconsistencies, Microsoft found, remained visible to defenders. The forgery was designed to make the request look like a decision that had already been made.

That same look-alike discipline extended to how the templates themselves were built. Microsoft found markers consistent with AI-assisted generation across the samples it reviewed — “extensive HTML comments, structured section labeling, and highly uniform template construction” — without establishing how much of the campaign’s content AI actually wrote. Across those samples, invoice identifiers and narrative structure held largely constant while organization-specific details changed — which Microsoft reads as one possible indication of a template built once and reused across targets.

Microsoft’s own conclusion closes the loop on who was actually involved: “Microsoft found no evidence that the legitimate organizations referenced in the lures, including ServiceNow, were compromised or involved in the activity.” ServiceNow never sent an invoice. The named executives never approved a payment. The identities were real. Their purported participation was fabricated.

The company was real. The executive was real. The vendor was real. The approval between them was fabricated.

The lure imitated more than ServiceNow. It imitated an approval that never happened.

Anatomy of a fabricated approval

A familiar name can invite recognition before verification begins. The attack was designed to exploit that interval — it needed the recipient to encounter what looked like an already-settled decision instead of an unapproved request. Microsoft’s own analysis found real, visible defects in the fabricated thread: mismatched headers, an inconsistent display name, and wording a careful reader could catch. The attackers deployed the same structure at industrial scale despite those defects.

The invoice supplied the demand. The fabricated conversation supplied its supposed permission. Verifying an approval requires evidence from outside the request itself — a second channel, a verified callback, a record that exists independent of the email asking for the money. A convincing story about approval is not evidence of it, no matter how coherent the story reads.

This is a hostile mirror of Digital Derangement Syndrome. Across this record, we have repeatedly documented real standing going unrecognized because its signals were fragmented or unverified. Here, fabricated approval was built to borrow the credibility of real names, a real company, and a real vendor. The distinction that matters isn’t how convincing the story is. It’s whether the authority behind it was ever verified independent of the story telling it.

The Agentics read

Answer Engine Authority runs on the same discipline for identity that this campaign lacked: verified standing first, recognition built on top of it, never the other way around. Whether or not AI wrote a line of it, an attacker deployed a fabricated approval history at industrial scale through attacker-controlled infrastructure, aimed at accounts-payable desks, documented defects and all. “Microsoft found no evidence that the legitimate organizations referenced in the lures, including ServiceNow, were compromised or involved in the activity.” Through the Agentics lens, this is the hostile mirror: trust attached to real names was solicited by a story about them that had never been independently verified. The correction isn’t assuming a familiar name means the request behind it is real. It’s having a way to check.

Sources

Campaign details come from Microsoft’s own security research: the August 3–5, 2026 window, the >1,000,000-email volume targeting enterprise users, the 87.7% U.S.-targeting figure, the service-nowinc[.]com and domainlify[.]net domain registrations, the nearly-$50,000 ACH ask, the AI-generation-consistent template markers, Microsoft’s own documented defects in the fabricated thread, and Microsoft’s statement that it found no evidence that the legitimate organizations referenced in the lures, including ServiceNow, were compromised or involved in the activity — Microsoft Security Blog.

A familiar name is a claim.
What corroborates it?

A consistent story is not the same as a verified one. Answer Engine Authority builds corroborating signals so recognition can rest on verified standing, not familiarity alone. For your own authority: what corroborates your name, independent of the story being told about it? Bring that question to SIA — the Intelligence Officer.

Every edition, in order, from No. 001 · A new edition releases daily, 05:30 CT.

Open the Record
‹ Edition No. 074 Next Dispatch — releases 05:30 CT ›