How Compromised Third-Party Inboxes Put Your Business at Risk

How Compromised Third-Party Inboxes Put Your Business at Risk

October 09, 2026 / in Blog / by Zafar Khan, RPost CEO

Microsoft reveals 12k+ compromised inboxes across 10,000 orgs.

Rocky the Raptor here, RPost’s cybersecurity product evangelist. I've noticed something interesting about cybersecurity conversations. Nearly everyone believes their organization is reasonably secure. Maybe not perfectly secure, but certainly more secure than some of the suppliers, customers, law firms, consultants, and other third parties they communicate with every day. And that's probably true for many organizations.

But there is a nagging question behind all the talk about third-party compromise: Are there really that many compromised email accounts out there? And how difficult is it for a cybercriminal to get into one?

Cybercrime is Becoming a Subscription Business

Microsoft recently provided a rather unsettling answer. In a September 22 research report, Microsoft exposed a cybercrime platform called EvilTokens, which it says facilitated the compromise of more than 12,000 email inboxes across 10,000 organizations worldwide in just the last few months. And this is just one of the many similar cybercriminal-offered tools (for example, Tycoon2FA-related phishing campaigns, per Microsoft, reach more than 500,000 organizations each month). 

In February 2026, EvilTokens quickly became one of the most widely used phishing-as-a-service offerings. Its customers weren't necessarily brilliant hackers - they were subscribers. The price? According to Microsoft, $1,500 to get started and $500 a month thereafter!

Think about that. For less than the cost of many ordinary business software subscriptions, a criminal could rent sophisticated technology designed to compromise Microsoft 365 accounts, complete with phishing templates, AI assistance, victim tracking, and tools for analyzing stolen inboxes. The mechanics are remarkably simple from the victim's perspective.

How a Legitimate Microsoft Login Becomes an Attack

Imagine an employee at your trusted accounting firm receives what appears to be a Microsoft (or Adobe, or Dropbox, or Slack, or LinkedIn or …) related request to access a document. They click a link, see a code, and are directed to Microsoft's (or the other platform’s) legitimate device sign-in website. They enter the code and authenticate, possibly even completing multifactor authentication.

Everything looks Microsoft-reassuring. Unfortunately, the criminal initiated the authentication request. By entering the code, the employee has unknowingly authorized the criminal's session. The attacker may gain account access without ever learning the employee's password. As a simple example, they can capture the browser post-authentication access token (you know, that long string of characters in the browser you often see after logging in) and then copy it, and paste it into any computer and they are logged in remotely. If they paste the token into a computer running through a virtual server hosted in your geolocation, they can circumvent many alarms, so they do.

Microsoft calls this device code phishing - an abuse of a legitimate authentication process originally designed for devices such as smart TVs and conferencing equipment. Others call it proxy phishing.

The Real Danger Begins After the Inbox is Compromised

And then the interesting part begins. Microsoft reports that EvilTokens uses AI to analyze compromised inboxes, identify executives and financial decision-makers, examine invoices and wire-transfer discussions, and map organizational relationships. 

EvilTokens platform showing options for managing captured tokens

[Image of Post-Access EvilTokens Management Console – Source: Microsoft]

Criminals can create hidden inbox rules, maintain access, and study conversations before launching fraud. The account owner may have no idea someone else is reading along. The criminal doesn't necessarily need to strike immediately – or even read the email (remember, AI is reading it for them in whatever language and alerting them when there is a message of cybercrime usefulness).

A compromised account can provide intelligence for a later attack, whether the original operator or someone else who later gains access. 

Your Security Doesn't End at Your Organization's Perimeter

Now consider your organization. You may have invested millions securing your own environment. Yet you routinely send sensitive information to people whose security you neither control nor continuously verify. 

Encryption protects information in transit, but it doesn't confirm that the legitimate recipient's account is uncompromised or let you control what happens to the content afterward. A recipient might unknowingly expose your strategy to an attacker already inside their mailbox. Another might innocently upload your confidential document into an unauthorized AI service. A malicious insider could forward it elsewhere. 

Once the information leaves your environment, traditional security visibility often ends. This is precisely the blind spot RAPTOR™ AI by RPost was designed to address.

See the UnseenTM Before Cybercriminals Strike

RMail® and RDocs® can transform selected communications and documents into instruments of intelligence. As recipients interact with protected content, protocol-level signals can reveal unusual access patterns, suspicious infrastructure, and potentially adversarial reconnaissance beyond the sender's endpoints.

RAPTOR™ AI analyzes those signals to help distinguish ordinary recipient behavior from suspicious activity. Rather than waiting for a fraudulent invoice or convincing impersonation, PRE-Crime™ cyber counterintelligence looks for signs that someone may already be gathering the information needed to prepare the attack from well masked protocol fingerprints that RAPTOR has previously associated with a cybercriminal. Importantly, these capabilities can operate without RPost storing the underlying messages or documents.

Microsoft's EvilTokens and Tycoon2FA  research is an important reminder that sophisticated cybercrime is increasingly available as a subscription service. AI makes compromised information easier to analyze, and the resulting intelligence can make subsequent fraud frighteningly convincing.

The larger cybersecurity question is no longer simply whether your own email is secure; it’s who else may be reading the information you send to people you trust. And perhaps the most important question of all: can you see the criminal studying your business before the criminal decides to strike?

That's where this RAPTOR™ AI likes to hunt.