Contacts
Book a Meet
Close

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

2095 (1)

EvilTokens: When AI Helps Phishing Look Like Real Business Communication

What Happened

Microsoft said it worked with partners to disrupt key infrastructure used by EvilTokens, a cybercrime platform that used AI to prepare and support phishing attacks.

According to Microsoft, EvilTokens was linked to more than 12,000 compromised inboxes across more than 10,000 organizations worldwide. Cloudflare also confirmed its role in the operation and described an embedded AI coach that guided criminals on topics such as tax documents, BEC (Business Email Compromise) and typical invoice and accounting correspondence.

Why This Matters

EvilTokens was not just another phishing tool. The platform combined account compromise, compromised mailbox analysis, target selection and preparation for payment fraud.

AI does not make the attack “magic.” It helps attackers move faster and sound more convincing. For example, it can analyze a mailbox, identify trusted contacts, payment workflows, approvals and the right moment for fraud.

This makes attacks harder to detect because the message can look like part of a real business conversation.

What Organizations Should Check

Practical checks:

  • whether defenses against token theft and device code phishing are in place;
  • whether unusual Microsoft 365 account sign-ins are monitored;
  • whether alerts exist for new devices, new sessions and unusual locations;
  • whether email forwarding rules are reviewed;
  • whether mailbox changes and delegated permissions are monitored;
  • whether finance teams verify IBAN, invoice and payment changes through a second channel;
  • whether there is a process to revoke active sessions and reset passwords quickly;
  • whether compromised accounts are monitored for follow-on fraud.

DIAMATIX Comment

From the DIAMATIX perspective, this case shows why identity and mailbox protection are now part of business resilience.

When an attacker enters a real mailbox, they no longer need crude phishing. They can read the context, understand who approves payments, which partners are trusted and what normal communication looks like.

SOC (Security Operations Center) and MDR (Managed Detection and Response) processes need to connect signals from accounts, email, endpoints, cloud services and business workflows. Only then can teams distinguish normal communication from prepared fraud.

AI will make phishing faster and more personalized. Defense needs stronger visibility, access control and clear procedures for suspicious payments.

Check whether mailbox accounts are a blind spot

DIAMATIX can help assess Microsoft 365 security, access control, account visibility and response readiness for phishing, token theft and business email compromise.

Request an identity and email security risk review with DIAMATIX.
Trusted · Innovative · Vigilant


Sources

  • Microsoft. Disrupting EvilTokens: The AI Chatbot Built for Cybercrime.
  • Microsoft Security Blog. Unmasking EvilTokens: Getting to the root of device code phishing.
  • Cloudflare. Cloudflare participates in global operation to disrupt EvilTokens Phishing-as-a-Service.
  • Help Net Security. Microsoft disrupts EvilTokens phishing service that gave criminals access to 12,000 inboxes.
  • BleepingComputer. EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts.

This article summarizes publicly available information as of September 2026.

Subscribe for latest updates & insights

Please enable JavaScript in your browser to complete this form.