AI-powered business email compromise warning for regulated organizations

AI-Powered Business Email Compromise Warning for Regulated Organizations: Evil Tokens 2026

Recently, Microsoft linked EvilTokens to more than 12,000 compromised inboxes across more than 10,000 organizations. The warning comes after what happened when attackers got inside: AI could help turn ordinary business email into a map of financial relationships, payment conversations, and the people trusted to move money.

September 30, 2026 Author: Zach Carothers Reviewed By: Benjamin Ross 5 min read AI Governance, Email Compromise Cybersecurity & Regulated Industries

Executive Summary

EvilTokens is an important example of how artificial intelligence is changing business email compromise. Criminals have always studied executives, finance teams, vendors, and approval processes before attempting fraud. Now, AI can perform much of that research faster by organizing a compromised mailbox and identifying the conversations and senders that are the most useful to an attacker.

For regulated organizations, the concern extends far beyond financial advisers. Credit unions, healthcare organizations, schools, government agencies, manufacturers, and other regulated businesses all use email to coordinate sensitive work. A compromised mailbox can reveal who approves payments, which vendors are trusted, what normal requests look like, and how employees communicate.

For regulated organizations, EvilTokens is one of 2026’s clearest warnings about AI-powered business email compromise.

We are not trying to convince businesses to stop using AI. Our point is that AI adoption, identity security, email security, and human approval can no longer be treated as separate conversations.

What made EvilTokens different from normal phishing?

EvilTokens primarily used device-code phishing, which abuses a legitimate Microsoft authentication process. A victim could be sent to Microsoft’s real sign-in page, enter a code, and complete what appeared to be a normal authentication process while unknowingly authorizing the hacker’s session.

Once inside, the AI component could analyze the mailbox for useful context. Microsoft documented capabilities for locating wire-transfer conversations, vendor invoices, financial relationships, and the people that it referred to as the organization’s “money movers,” while even helping attackers determine who the next best hit could be.

We have covered the mechanics of business email compromise and wire fraud before. EvilTokens adds an important new layer: AI can accelerate the research that makes a fraudulent request look legitimate.

Why does AI-powered email change business risk?

The same capability that makes AI useful to employees can make a stolen mailbox more valuable to a criminal. AI is particularly good at summarizing large amounts of information, identifying relationships, and finding relevant details inside unstructured text. Business email contains enormous amounts of exactly that kind of information.

That does not mean Microsoft Copilot, ChatGPT, or another legitimate AI assistant caused the EvilTokens attack. The broader issue is access and authority. As organizations connect AI to email, documents, meetings, and business systems, leadership needs to understand what those systems can see, what they are allowed to do, and what happens when an identity or permission is compromised.

That is the core of modern AI governance and identity controls and human-in-the-loop AI workflow design . Useful AI should have defined permissions, clear ownership, audit visibility, and human approval where an action can affect money, sensitive information, security, or compliance.

For RIAs, the issue also intersects with the SEC’s 2026 Examination Priorities, which include cybersecurity controls, risks associated with AI, customer account takeovers, and fraudulent transfers. Our existing guide to what RIA executives should do about AI governance goes deeper into that regulatory side.

What should regulated organizations do now?

Start by assuming that a believable email can still be fraudulent. Requests involving new payment instructions, changed bank accounts, unusual wires, access changes, or other high-risk actions should require independent verification through a trusted channel already established by the organization. Microsoft specifically recommends separate verification when a request involves redirecting funds, changing payment information, or approving an unusual transaction.

Microsoft also recommends blocking device-code authentication where it is not needed and moving toward phishing-resistant authentication. Organizations should monitor identities and email closely enough to recognize suspicious sessions, unusual mailbox rules, token abuse, device registrations, and other activity that may indicate a real account has been compromised.

In Microsoft 365 environments, identity protection, email security, detection, and incident response should operate as one program rather than separate tools. TorchLight’s managed security model for identity takeovers and payment fraud is built around that principle.

If an attacker gained access to a real executive or finance mailbox today, what would still prevent that access from becoming a financial loss, privacy incident, or regulatory problem?

The Technical Side

EvilTokens abused Microsoft’s OAuth device authorization flow. The attacker initiated a device-code request and convinced the victim to enter that code through Microsoft’s legitimate device-login process. The resulting authorization could give the attacker valid access tokens without requiring them to directly capture the victim’s password.

Microsoft also observed mailbox reconnaissance, Microsoft Graph activity, malicious inbox rules, and device registration. That is why changing a password probably won’t fully contain this type of compromise by itself. Response may also require revoking sessions and refresh tokens, reviewing mailbox rules and registered devices, and investigating how the compromised identity was used.

One final clarification matters: Microsoft linked EvilTokens to more than 12,000 compromised inboxes across more than 10,000 organizations, but its public reporting does not establish that the AI component analyzed every one of those mailboxes.

The Cybersecurity Takeaway

EvilTokens was disrupted, but the model it demonstrated is unlikely to disappear. AI can help attackers understand a compromised organization faster at the same time businesses are giving legitimate AI systems deeper access to email, documents, meetings, and workflows.

That makes governance, identity security, monitoring, and human approval more important than ever. The goal is to know what AI can see, what it is allowed to do, and which decisions still require a person before money, data, or access changes hands.

AI access is becoming a cybersecurity decision.

As AI gains access to email, files, meetings, identities, and business workflows, regulated organizations need more than an acceptable-use policy. They need clear permissions, visibility, monitoring, and human approval around the actions that can create real financial, security, or compliance consequences.

TorchLight connects AI governance, workflow automation, Microsoft 365 identity security, and managed cybersecurity so organizations can use AI productively without losing control of the systems and information it touches.

Resources