
AI phishing attacks represent a fundamental shift in how criminals target small and mid-sized businesses. A new service called EvilTokens demonstrates exactly how sophisticated these threats have become: it doesn’t just steal your Microsoft 365 login credentials, it uses artificial intelligence to decide which of your employees is the most valuable target for follow-up scams. For an SMB owner, this means a single compromised account can cascade into wire fraud, vendor payment theft, or a full business email compromise before anyone notices something is wrong.
What makes AI phishing attacks different from traditional email scams?
Traditional phishing emails cast a wide net. Attackers send thousands of generic messages hoping someone clicks a malicious link or enters credentials on a fake login page. You’ve seen them: the urgent password reset, the shipping notification, the Payroll department request that doesn’t quite sound right.
AI phishing attacks work differently. They steal session tokens, small files your browser uses to remember that you’ve already logged in. Once an attacker has your session token, they don’t need your password. They don’t need to bypass your multi-factor authentication. They simply step into your active session as if they were you, sitting at your desk, already logged in.
EvilTokens takes this a step further. After stealing session access, the tool’s AI reads through your emails, Teams messages, and SharePoint documents. It builds a profile: Who do you communicate with? What vendors do you work with? What projects are active? Who reports to you? Then it scores each contact based on financial access and authority, essentially creating a target list of who to scam next.
For a manufacturing company, this might mean the attacker identifies your accounts payable clerk and your relationship with a key supplier, then sends a perfectly timed invoice change request that references a real purchase order. For a professional services firm, it could mean impersonating a partner to redirect a client payment to a fraudulent account.
How do criminals actually steal Microsoft 365 session tokens?
Session token theft starts with a phishing page that looks identical to the real Microsoft login screen. An employee receives an email (sometimes from a compromised colleague’s account) with a link to review a shared document or approve a request. The page asks them to log in. They enter credentials, complete multi-factor authentication, and think they’ve accessed the file.
Behind the scenes, the fake page captures not just the password but the session token that Microsoft issues after successful login. That token can remain valid for hours or even days, depending on your organization’s policies. The attacker imports the token into their own browser and gains immediate access to email, files, and any Microsoft 365 service the employee can reach.
What makes this particularly dangerous for SMBs is speed. Within minutes of token theft, automated AI tools begin analyzing your data. They’re looking for patterns: recurring invoices, upcoming payments, clients in the middle of transactions, employees who can approve wire transfers. This reconnaissance happens silently while the legitimate employee goes about their day, unaware their session was duplicated.
The analysis isn’t random. The AI looks for specific indicators of value. Does this person have access to accounting systems? Do they communicate with banks or financial institutions? Are there emails discussing upcoming payments or contract renewals? The system ranks potential targets and attack scenarios, then hands attackers a roadmap of exactly who to impersonate and what requests will seem most plausible.
Why do AI-generated phishing messages fool employees who know to be careful?
Your team has been trained. They know not to click suspicious links. They’ve heard the warnings about urgency and poor grammar in phishing emails. So why do AI phishing attacks still work?
Because the messages are perfect. AI tools analyze thousands of real emails from your organization to learn your communication style. They know whether your CEO writes in short sentences or long paragraphs. They know if your accounting department uses specific subject line formats. They understand which vendors you work with and how invoices are typically discussed.
When the AI composes a phishing message, it doesn’t look like spam. It looks like Tuesday. The sender is someone the recipient knows. The project referenced is real. The invoice amount matches typical vendor patterns. The writing style is identical to past emails from that sender because the AI literally studied those past emails.
Traditional email security tools struggle here. They’re designed to catch anomalies: weird links, blacklisted senders, grammatical patterns common in scam emails. AI-generated messages contain none of these red flags. The links go to legitimate-looking domains (sometimes compromised legitimate domains). The sender is an internal account or a recently compromised partner. The grammar and tone are indistinguishable from real communication.
For an SMB, this creates a difficult problem. You can’t tell employees to ignore all payment requests or vendor communications. Business has to continue. But without technical controls to detect session hijacking and abnormal access patterns, you’re relying entirely on human judgment to spot a message that was specifically designed by machine learning to be undetectable.
What specific risks do AI phishing attacks create for professional services and manufacturing companies?
Professional services firms face concentrated risk because client trust is the entire business model. When an attacker compromises a senior associate’s Microsoft 365 account, they gain access to active client matters, fee agreements, and trust account details. A single AI-generated email asking a client to redirect a retainer payment can result in six-figure theft and immediate reputational damage. The client doesn’t blame the criminal. They blame you for not protecting their money.
Law firms and accounting practices have additional exposure through the sensitive data in emails and documents. An attacker with session access doesn’t just see one client’s information. They see everything: merger discussions, litigation strategy, tax records, regulatory filings. That information has resale value to competitors or can be used for secondary extortion. Even if no money is stolen, the disclosure itself may trigger malpractice claims and regulatory reporting obligations.
Manufacturing and industrial companies face different but equally serious risks. AI phishing attacks targeting these businesses focus on supply chain and vendor relationships. The attacker identifies key suppliers, studies past purchase orders and payment patterns, then sends invoice updates or bank account change requests that align perfectly with expected transactions. A manufacturer expecting a $150,000 steel delivery won’t question a payment redirect email that references the correct PO number, delivery date, and pricing because the AI pulled all those details from compromised email.
Production disruption is another concern. If an attacker gains access to accounts connected to enterprise resource planning systems or manufacturing execution systems, AI analysis can identify which systems are critical and which employees have administrative access. The phishing campaign then targets those specific individuals to establish persistence for ransomware deployment or operational technology attacks.
Do standard security tools prevent AI phishing attacks, or do you need something different?
Standard email filtering catches a percentage of AI phishing attacks, but not enough to rely on it as your only defense. Traditional filters look for known malicious links, sender reputation issues, and content patterns associated with spam. AI-generated phishing often bypasses all three because it uses compromised legitimate accounts, references real relationships, and contains no obvious malicious payload in the initial email.
Multi-factor authentication helps, but session token theft renders it incomplete protection. Once the attacker has a valid session token, MFA has already been satisfied. The system sees the token and grants access without asking for a second factor again. This is why you can close your laptop, reopen it an hour later, and still be logged into your email without re-authenticating.
What does work is conditional access policies that treat each session decision as ongoing, not one-time. Instead of asking “Did this user prove their identity once?” the system continuously asks “Does this session still look legitimate?” That means checking: Is the login coming from the expected geographic location? Is the device registered and compliant? Has the user’s risk score changed based on recent activity? Is the access pattern normal for this person?
Session lifetime policies also matter. Many SMBs leave Microsoft 365 configured with default session timeout settings that keep tokens valid for extended periods. Shortening session lifetime to a few hours means even if a token is stolen, it expires relatively quickly. Require re-authentication for sensitive actions (like changing bank details or approving large payments) even within an active session.
Monitoring is the other critical layer. Security information and event management (SIEM) tools or Microsoft’s built-in logging can detect anomalies: a user accessing unusual amounts of email, downloading contact lists they don’t normally touch, logging in from a new device or location. None of these indicators alone proves compromise, but combined they warrant investigation. For an SMB, this often means working with a managed security partner who monitors these signals and responds before the attacker completes their objective.
What employee training actually reduces risk from AI phishing attacks?
Generic phishing training that shows obvious spam examples doesn’t prepare employees for AI phishing attacks. Your team needs to understand that the most dangerous messages will look completely legitimate. The training focus should shift from “spot the suspicious email” to “verify through a second channel.”
Establish a clear verification protocol for specific high-risk requests: payment changes, wire transfers, sensitive data sharing, or credential requests. The rule is simple: if someone asks you to do any of these things via email or Teams, verify through a different communication method before acting. Call the person using a number you already have saved (not one provided in the message). Walk to their desk. Send a text. The method doesn’t matter as much as the principle that you never act on financial or sensitive requests based solely on a single digital message.
Train employees on session security behaviors. Log out when you’re done, especially on shared or public devices. Be suspicious if you’re unexpectedly asked to re-authenticate, particularly if the request comes after clicking a link in an email. Understand that once you’ve logged in somewhere, attackers may be able to maintain access even after you’ve left.
Run realistic simulations using the same techniques attackers use. Send test phishing messages that reference real projects, come from compromised-looking internal addresses, and ask for actions people perform daily. Track not just who clicks, but who verifies before acting. Reward the employees who call IT to report suspicious messages, even if the message turns out to be legitimate. You want a culture where verification is normal, not paranoid.
Make reporting easy and consequence-free. Employees won’t report potential phishing if they fear being blamed or shamed. When someone does click a malicious link or enter credentials on a fake page, you need them to report it immediately so IT can invalidate the session token and contain the incident. Every hour of delay gives attackers more time to analyze data and launch follow-up scams.
How much does protection against AI phishing attacks cost, and is it worth it for an SMB?
The cost question has three layers: technology, labor, and opportunity cost of a successful attack.
Technology costs for SMB-appropriate protection start around $5 to $15 per user per month for advanced email security with AI detection, conditional access capabilities, and session monitoring. Microsoft 365 E5 or Business Premium licenses include many of these features. Third-party email security platforms (Proofpoint, Mimecast, Abnormal Security) add another layer of AI-driven detection. For a 50-person company, you’re looking at $250 to $750 monthly.
Labor costs depend on whether you handle security monitoring internally or through a managed service. Effective monitoring of session anomalies, access patterns, and phishing indicators requires dedicated attention and expertise. Most SMBs don’t have a full-time security analyst, so this work falls to a managed security service provider. Expect $1,500 to $5,000 monthly depending on scope, which includes monitoring, incident response, and ongoing security policy tuning.
The opportunity cost calculation is straightforward: what does a successful attack cost? Wire fraud targeting SMBs averages $50,000 to $150,000 per incident, and recovery is unlikely (FBI reports less than 15% of business email compromise funds are recovered). Add the time cost of incident response, notification obligations if client data was exposed, potential legal claims, and reputational damage. For professional services firms, losing a single major client over a security incident can cost far more than the direct theft.
Is it worth it? If your business handles client funds, processes payments to vendors, or stores sensitive client information, the protection cost is a fraction of your exposure. Even one prevented payment fraud incident pays for years of security investment. For businesses with thin margins, start with the basics (proper licensing, conditional access, verification protocols) and add monitoring as budget allows. The worst strategy is doing nothing because comprehensive protection feels expensive.
What policy changes should an SMB make immediately to reduce AI phishing attack risk?
Start with a financial transaction verification policy that requires out-of-band confirmation. Any request to change payment details, initiate a wire transfer, or redirect funds must be verified through a phone call to a known number or in-person confirmation. This policy applies even if the request comes from the CEO. Make the verification requirement non-negotiable and part of your standard operating procedures, not an optional security suggestion.
Implement session timeout and conditional access policies in Microsoft 365 or your email platform. Set session lifetime to four hours or less. Require re-authentication when accessing sensitive data or performing high-risk actions. Configure conditional access to block or require additional verification for logins from unfamiliar locations, unmanaged devices, or connections showing other risk indicators. Your IT provider or managed service partner can configure these settings in an afternoon.
Establish a clear incident reporting procedure. Employees need to know exactly who to contact if they suspect phishing, accidentally click a suspicious link, or notice unusual account activity. The report should trigger immediate action: session token invalidation, password reset, account activity review, and monitoring for follow-up attacks. Speed matters because attackers move quickly once they have access.
Limit data access based on role. Not everyone needs access to all client files, all vendor records, or all financial information. Proper access controls reduce the damage from any single compromised account. If your accounts payable clerk’s account is hijacked, the attacker shouldn’t also gain access to client lists, strategic plans, or HR records. Segment access so compromise of one account doesn’t provide comprehensive organizational reconnaissance.
Review and document your vendor communication procedures. How do vendors normally communicate payment changes? What information do they include? Who on your team is authorized to approve these changes? Creating a documented baseline makes it easier to spot deviations. Train accounting and purchasing staff to be especially skeptical of urgent requests, pressure to act quickly, or any communication that breaks the normal pattern.
Keep reading
Sources
Source: EvilTokens Doesn’t Just Steal Microsoft Sessions, Its AI Tells Attackers Who to Scam Next