Phishing has always relied on one basic idea: make a message convincing enough that someone trusts it.
Artificial intelligence is making that much easier.
In September 2026, Microsoft announced the disruption of EvilTokens, an AI-powered phishing-as-a-service platform linked to more than 12,000 compromised email inboxes across more than 10,000 organizations worldwide. Victims spanned industries including construction, financial services, real estate, healthcare, higher education, and wholesale distribution.
What makes this threat worth paying attention to isn't simply the number of accounts compromised.
It's what attackers were able to do once they got inside.
Phishing Is Becoming More Personal
Traditional phishing attacks often give themselves away.
The wording feels strange. The request doesn't make sense. The sender doesn't sound quite right.
EvilTokens showed how AI can change that equation.
According to Microsoft, attackers could use the platform's AI capabilities to analyze a compromised inbox, understand relationships within an organization, identify people involved in financial decisions, find invoices and payment conversations, and determine which trusted contacts would be most useful to impersonate.
In other words, attackers weren't simply using AI to write a better phishing email.
They were using AI to understand the business behind the inbox.
That makes social engineering considerably more convincing.
An attacker who understands who your vendors are, who approves payments, which projects are underway, and how employees normally communicate has a much better chance of creating a request that feels legitimate.
The Password Isn't Always the Target
EvilTokens also highlights another important shift in phishing attacks: stealing a password isn't necessarily the goal.
The platform used a technique known as device code phishing.
Device code authentication is a legitimate Microsoft authentication process commonly used for devices that don't support a traditional sign-in experience. Attackers abuse that process by convincing a user to enter a code associated with the attacker's session.
The employee may even complete the process through Microsoft's legitimate sign-in page.
If successful, the attacker can obtain authentication tokens that provide access to the account without directly stealing the user's password.
That distinction matters because businesses often assume that multifactor authentication alone will stop an account takeover.
MFA remains an important security control, but attackers are actively developing techniques designed to work around traditional authentication processes.
What Happens After an Inbox Is Compromised?
This is where AI creates an even bigger problem.
Historically, gaining access to an email account was only the beginning. An attacker might need significant time to manually review messages, understand the organization, identify valuable targets, and determine how to monetize the breach.
AI can dramatically accelerate that process.
Microsoft found that EvilTokens could analyze mailbox activity to identify high-value targets, organizational relationships, financial conversations, wire transfer information, invoices, and executive correspondence. Attackers could then use that intelligence to support additional phishing and business email compromise attempts.
For businesses, that means the window between account compromise and potential fraud is getting smaller.
How Businesses Can Respond
The answer isn't to tell employees to simply "look more closely" at their email.
Employees should absolutely be trained to recognize suspicious requests, but businesses also need security controls designed around the reality that phishing messages are becoming more sophisticated.
Microsoft recommends several protections against attacks like EvilTokens, including stronger Conditional Access policies, phishing-resistant authentication methods, Safe Links protections, monitoring risky sign-ins, detecting suspicious inbox rules, and restricting device code authentication when it isn't required.
Businesses should also establish clear procedures for financial requests.
A request to change banking information, redirect a payment, purchase gift cards, or make an unusual transfer shouldn't be trusted simply because it appears to come from a familiar email account.
Verify sensitive requests through a second trusted communication channel.
The Bigger Lesson From EvilTokens
Microsoft and its partners disrupted infrastructure associated with EvilTokens in September, including seizing 50 websites and disabling more than 150 additional domains tied to the operation.
But EvilTokens represents something bigger than one cybercrime platform.
AI is giving attackers tools that can help them understand businesses, personalize attacks, and operate at a scale that previously required considerably more time and expertise.
The question for business leaders isn't whether employees will become perfect at identifying phishing emails.
They won't.
The better question is:
If someone makes a mistake, do you have enough layers of protection in place to keep that mistake from becoming a business-wide incident?
That's where the right combination of technology, identity protection, employee awareness, monitoring, and security processes makes the difference.
At Common Knowledge Technology, we help organizations look beyond individual security tools and build a cybersecurity strategy around how people actually work and how today's threats actually operate.
Because as attackers get smarter, your security strategy needs to keep up. Contact us to stay ahead of the latest threats: https://www.ck-tek.com/contact-us/

