Microsoft Detects 1 Million AI Scam Emails in 3 Days — Japan Suffers Losses Exceeding ¥2 Billion
機械翻訳 / Machine-translated

機械翻訳 / Machine-translated
@aifriends
AI Friends(https://aifriends.jp)のクロスポスト公式アカウント。AIツールの紹介・使い方・できることを、中学生でもわかるやさしい日本語で届けます。
What You'll Learn from This Article
Over the three-day period from August 3 to 5, 2026, Microsoft detected more than 1 million scam emails. These were carefully crafted using AI, impersonating CEOs and company chairpersons.
The attackers exploited multiple email delivery services and primarily targeted the accounting departments of U.S. companies. The fraudulent pretext was an "annual contract for ServiceNow (an enterprise business platform)," using the name of a real service to lend credibility.
The scam emails were extremely sophisticated. In addition to forged invoices demanding transfers of approximately ¥7.5 million per case, the attackers even fabricated multiple fake email threads.
Phrased as "regarding the matter the CEO instructed last week," the emails were designed to appear as though an ongoing exchange had already taken place. The attackers registered a fake domain, "service-nowinc[.]com," and began operating it the very next day.
Microsoft determined that these emails were AI-generated. The evidence came down to three points:
Emails written by humans have personality, but emails mass-generated by AI are "too clean." A 2024 survey found that 40% of phishing emails were AI-generated.
Since the start of 2026, nine companies associated with listed firms in Japan have fallen victim to business email compromise (BEC), with total damages exceeding approximately ¥2.09 billion.
In January 2026, a company in Sapporo received wire transfer instructions via social media from someone claiming to be the company president and was defrauded of ¥80 million. Globally, losses in 2024 totaled approximately ¥415.5 billion, with projections suggesting the figure could reach around ¥6 trillion by 2027.
You might think, "If a suspicious email arrives, just call to verify" — but even that conventional wisdom is losing its reliability.
Advances in AI voice synthesis technology (deepfake audio) now allow attackers to imitate an executive's voice with high accuracy. Attackers collect audio from interview videos of company presidents and reconstruct it using AI.
Combining three technologies — SPF, DKIM, and DMARC — allows you to block emails from fake domains before they even reach your inbox.
ZAP is a feature that automatically deletes emails identified as scams after they have already been received. It is available in Microsoft 365 and Google Workspace.
Attackers try to impair your judgment by applying pressure such as "this is urgent" or "it's a direct order from the president." Having rules in place buys you time to verify calmly.
While the advancement of AI brings greater convenience, it also enables increasingly sophisticated fraud tactics. Companies must become more alert to two warning signs — "emails that are written too well" and "urgent wire transfer requests" — and strengthen their defenses on both the technological and operational fronts.
This article is a cross-post from AI Friends.