← The Vault
The Big Story

How scammers use AI to trick employees

Cybercriminals are using AI chatbots to analyze stolen corporate emails, identifying who handles money and how to impersonate their managers. This automation turns a months-long task of hacking into a project that takes only minutes. While experts are working on better ways to test AI safety, these scams highlight why you should always verify unusual requests for money, even if they seem to come from a trusted colleague or boss.

Edition № 562Room: The Big Story22 September 20262 min readSources: 5
Article

Criminals have developed a new, automated way to trick employees into sending them money. Instead of spending weeks manually studying a hacked email account to learn a company's inner workings, they are now using AI to do the research for them.

WHAT'S HAPPENING

A platform called EvilTokens recently automated the process of stealing and abusing corporate email accounts. After gaining access to an employee's inbox, the software used an AI chatbot to read thousands of past emails. It quickly identified which employees had the authority to send money, who their managers were, and what their standard communication style looked like. The system then drafted convincing emails impersonating trusted contacts, asking targets to redirect payments to accounts controlled by the hackers. Microsoft recently led an operation to shut down this platform, seizing its websites and working with authorities to make arrests, but the incident reveals how quickly AI can scale up these kinds of digital scams.

The speed of the scam

HOW IT WORKS

To understand why this is a change, think of a traditional email hack like a burglar breaking into a library. To find the secret document they need, they have to physically scan thousands of books. This takes a long time and is prone to error. The AI tool acts like an expert librarian who can scan the entire collection in seconds. It looks for patterns—like invoices, bank authorizations, or specific phrases people use when discussing funds—and summarizes the most valuable information. Because the AI is trained to recognize these social and professional connections, it can generate a realistic lure that looks exactly like a message you would expect to receive from your boss. By the time an employee realizes something is wrong, the AI has already provided the criminal with a map of the company's relationships and the best way to exploit them.

WHY IT MATTERS

This type of crime moves much faster than the old, manual methods. When attackers have tools that can summarize days of research into minutes of output, they can cast a wider net across more organizations. It serves as a stark reminder that even if an email looks legitimate, the contents might be generated by a machine designed to mimic a trusted colleague. The best defense remains old-fashioned: if you receive an unexpected request to change payment information or move funds, do not rely on the digital message. Reach out through a separate, trusted channel—like a phone call or an in-person conversation—to verify the request before you act. In an era where AI can fake the tone and context of a professional relationship, verifying the person behind the screen is more important than ever.

Sources
← PreviousHow scientists are turning research papers into interactive AINext →Can you actually teach your music app what you like?
Tomorrow's edition · free

Liked this one? The next lands at breakfast.

Every story in tomorrow's AI news, rebuilt in plain English — five minutes, sources linked, free forever.

By joining you agree to receive Article's daily newsletter — unsubscribe in one click. Privacy

← Back to the Vault