Microsoft disrupted EvilTokens, a cybercrime platform that combined phishing, access theft, and artificial intelligence to turn compromised email inboxes into raw material for financial fraud. Since February, the service has been associated with more than 12,000 compromised inboxes across more than 10,000 organizations. The most relevant point, however, lies in what happened after the intrusion: the AI could analyze messages, business relationships, and payment authorizations to indicate whom to attack, whom to impersonate, and which scam had the greatest chance of working.

EvilTokens shows an important shift in the economics of business email compromise, or BEC. The reconnaissance work that traditionally required time and expertise may begin to be automated. If this model spreads, protecting the account will remain essential, but it will no longer be enough to think of defense only as a barrier against phishing. Companies will also need to reduce the operational value that an attacker can quickly extract from a single compromised identity.

The BEC bottleneck was after the intrusion

BEC fraud traditionally depends on context. Controlling an email inbox is not enough: the criminal needs to discover suppliers, financial officers, recurring payments, hierarchies, and communication patterns before choosing the right moment and identity for a fraud attempt.

The FBI itself describes campaigns in which criminals remain for weeks or months observing suppliers, billing systems, and executives' habits before sending fraudulent requests. This reconnaissance allows a fake transfer to appear part of a legitimate operation.

EvilTokens compressed part of this work. According to Microsoft, its assistant could comb through a compromised inbox looking for discussions about transfers, invoices, people capable of moving money, and contacts suitable for impersonation. The platform also performed reconnaissance via Microsoft Graph to map organizational structure and permissions.

It is this automation, more than the simple generation of phishing texts, that alters the economic model of the attack.

AI reduces the cost between stolen access and financial fraud

Generative tools had already been making another stage of fraud cheaper: producing messages, documents, and fake identities at large scale. In September, Microsoft itself detailed a campaign of more than 1 million emails that combined executive impersonation, fabricated invoices, and fake conversations to try to induce finance teams to authorize ACH payments close to US$ 50,000.

EvilTokens advances one stage. Instead of using AI only to fabricate content before the attack, the service applied models to private data obtained after the compromise.

This reduces the distance between gaining access and finding a monetization opportunity. An account with thousands of messages no longer necessarily requires hours of manual reading. Relationships with suppliers, approvals, financial responsibilities, and sensitive conversations can be prioritized automatically.

The platform also packaged these capabilities commercially. Microsoft states that access was sold for an initial fee of US$ 1,500 and a recurring subscription of US$ 500, with a control panel, phishing infrastructure, support, and tools to advance from compromise to fraud preparation.

In this sense, “fraud as a service” ceases to be just an analogy. The product reduced the need to separately combine knowledge about phishing, cloud identities, internal reconnaissance, and social engineering.

The time to react also becomes shorter

This automation creates another problem for defense: speed.

Microsoft's technical analysis found cases in which operators registered new devices less than ten minutes after the compromise to gain long-term persistence. In others, stolen tokens were used to create malicious inbox rules, exfiltrate emails, and continue reconnaissance while the access remained valid.

This means the window between the first sign of compromise and the start of exploitation of the corporate context can shrink significantly.

The attack also exploits a specific point of modern identity. EvilTokens abused device code authentication, a legitimate OAuth flow created for devices with limited interfaces. The victim could end up authorizing the attacker's session even while going through normal authentication steps on Microsoft's legitimate domain. For this reason, the company recommends blocking the device code flow when it is not necessary and strictly restricting its exceptions.

The consequence is that “having MFA” ceases to be a sufficient description of the security posture. The type of authentication, the allowed flows, the duration of tokens, the registration of new devices, and post-login behavior all begin to matter together. CISA recommends that organizations move to phishing-resistant methods, such as FIDO/WebAuthn, within a broader identity protection strategy.

Payments need to survive email compromise

The other necessary change is outside the security infrastructure.

In 2025, the FBI received nearly 25,000 reports of business email compromise, associated with approximately US$ 3 billion in losses. The figure helps explain why automating the search for financial opportunities inside compromised accounts has economic potential for cybercrime.

When an attacker can read real conversations, however, detecting fraud only by the tone of the message becomes less reliable. The attacker may know the supplier, the responsible executive, a previous invoice, and even the context of a real negotiation.

Therefore, the decisive control may be in the payment process. The FBI recommends that bank account changes, payment instructions, and transfers be verified through an independent channel, using previously known contacts instead of the information present in the received message itself.

This separation creates a barrier that automated inbox analysis does not easily eliminate: even understanding the compromised conversation perfectly, the criminal still needs to go through an authorization process that does not depend on it.

The EvilTokens model may survive EvilTokens

The operation against the platform was significant. Microsoft and Health-ISAC obtained a court order in the Eastern District of Virginia; Microsoft stated it seized 50 sites and took down more than 150 domains linked to the infrastructure. The action also involved technology and security companies, while British police arrested two men in an investigation related to the operation.

But taking down the infrastructure does not eliminate the economic logic demonstrated by the service.

The next relevant signal will be checking whether successor platforms begin to incorporate automated inbox analysis, organizational reconnaissance, and recommendation of monetization strategies as standard features. It will also be important to observe whether identity providers begin to more aggressively restrict flows such as device code authentication and automatically detect anomalous queries to Microsoft Graph after suspicious logins.

EvilTokens does not prove that all BEC will become automated. It shows something more concrete: part of the attack that historically depended on intensive human labor can now be packaged into software and sold by subscription.

For companies, this shortens the defensive assumption. A compromised email inbox should no longer be treated only as a source of stolen messages. It can function, almost immediately, as a map of the organization's relationships, authority, and financial flow.

More from Radar