Politics

Beyond phishing

The Column – Cyber ​​Security Week

There are probably people in companies who cannot explain precisely who authorizes a payment, which supplier gets paid on Friday, who replaces the CFO when he is traveling, and who the administration responds to without asking too many questions. Their inbox, however, probably knows it and the problem is that now even whoever stole it could find out.

EvilTokens, according to Microsoft, was born in February 2026 as a commercial phishing-as-a-service platform. Essentially a service for criminals: 1,500 dollars to enter, 500 per month and a series of tools with which to organize campaigns, manage infrastructures and compromise accounts. In about seven months, Microsoft linked it to the breach of more than 12,000 mailboxes belonging to more than 10,000 organizations around the world. It is an estimate of society, not a universal census of victims, but the dimensions still give an idea of ​​the phenomenon.

The first interesting aspect is how EvilTokens managed to gain entry. One of the tools was the so-called device code phishing, which exploits an absolutely legitimate function designed to authenticate devices on which typing a password would be inconvenient. The attacker generates a request and convinces the victim to complete it. The wonderfully disturbing thing is that the user can be on the real Microsoft site, see HTTPS, follow the normal procedure, and even complete multi-factor authentication. Everything works perfectly. Too bad he’s authorizing the criminal’s session.

So the MFA did its job exactly, but the human being did not understand on behalf of those who were using it. The system can authenticate our decision with great precision, but it cannot guarantee that we understood it.

Once inside, however, the criminal does not necessarily need the password because he has the tokens that allow him access and, if these are not revoked together with the sessions, simply changing the credentials may not be sufficient. This is also a small crack in our mental habits: we continue to automatically associate “compromised account” with “stolen password”, while the world had the bad idea of ​​becoming more complicated.

Up to this point, however, we are still in the area of ​​a cybercrime that we know well: criminal services sold as if they were company software, skills that can be purchased off the shelf and legitimate tools transformed into weapons. The really interesting passage comes next.

Imagine that you have just stolen a mailbox with ten thousand messages. You have years of invoices, meetings, orders, customers, suppliers and conversations ahead of you. Somewhere there is valuable information: who authorizes the transfers, which manager is traveling, which invoices are open, who trusts whom. Finding them, however, takes time because you have to read and above all understand.

EvilTokens delegated this job to artificial intelligence. According to Microsoft, the platform had tools to summarize and translate messages, identify financial conversations, reconstruct organizational roles and relationships of trust, up to identifying what we could call “money movers”: the people who can physically initiate payments.

Something changes here. That an artificial intelligence can write a good phishing email shouldn’t surprise anyone by now. However, the novelty is that it can help the criminal decide who to write it to, who to impersonate, which relationship to exploit and which transaction to try to intercept.

An inbox, looked at one message at a time, looks like an archive. Read all together it becomes something different. “Let’s proceed like last time”. “We are waiting for Laura’s authorization”. “The invoice will be paid on Friday.” “The director returns on Thursday”. Taken individually they are almost insignificant fragments. Connected together they describe processes, hierarchies, habits and trust. In practice, a kind of imperfect information twin of the organization.

Artificial intelligence makes it economically possible to transform that mass of information into operational knowledge. It not only automates the attack, but also some of the understanding needed to choose the attack.

It’s yet another bottleneck that cybercrime is eliminating. Over the years, technical expertise, infrastructure, malware, initial access and even ransomware as a service have become purchasable. It remained relatively expensive to understand a victim well. Now even that cognitive work can be compressed from days to minutes.

Microsoft also claims to have found indications that large parts of EvilTokens itself were developed using AI. We therefore have artificial intelligence to build the tool, then inside the tool to analyze the victims and, on the other hand, similar systems used to speed up the investigations. No war between conscious machines: just humans adding ever more powerful motors to their tools.

Perhaps we should then update our vocabulary too. We continue to talk about “data theft”, an expression that evokes files stolen from a digital drawer. EvilTokens suggests something more serious. A compromised mailbox can become a corporate memory that can be interrogated by the adversary, even while the organization that built it continues to consider it a simple collection of messages.

For years we have tried to prevent criminals from stealing our information. Now we also have to worry about their ability to understand them. Because a thief entering the house is a problem; someone who in a few minutes finds out where we keep the keys, who owns the safe and when we are out is already a different problem. They didn’t just steal what we know. They are learning to steal even the way we function.