EvilTokens uses language models to automate business email fraud

Sekoia has published part two of its analysis of EvilTokens, this time on how the service uses language models. According to the research, the AI integration can automatically scan thousands of stolen emails to identify high-value financial targets, map internal payment workflows and pinpoint key personnel. By analysing the professional tone and history of a victim's correspondence, the platform can autonomously generate credible, tailored attack scenarios and draft messages that are hard to distinguish from legitimate corporate communication. It operates through a Telegram-based ecosystem that lets even low-skilled affiliates run precision-targeted financial fraud at scale.

What this means for your organisation

The advice to look for poor language and odd phrasing is out of date. What now separates a fraudulent message from a genuine one is not how it is written, but whether the request itself is verified. This lands squarely on the finance function: an email referencing the right project, the right person and the right tone, asking for a changed account number, will look entirely normal. The defence has to move from the text to the process.

Berigo recommends

  • Require out-of-band confirmation for every change of bank account or payment details, with no exception for urgency.
  • Set a value threshold above which two people must approve, and let no individual override it.
  • Replace training in spotting bad language with training in following the payment process.
  • Rehearse a scenario where a supplier reports a new account number, with finance and management in the room.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch