Microsoft disrupts AI-assisted platform that compromised 12,000 accounts
Microsoft said it led a coordinated takedown of EvilTokens, a subscription-based cybercrime platform that used an AI-style chatbot to help attackers compromise about 12,000 Microsoft accounts across roughly 10,000 organizations. The service, marketed via Telegram in February, charged an initial $1,500 plus $500 monthly and automated many steps of large-scale email account compromise and fraud targeting.

Why It Matters
The disruption highlights how automation and AI can be repurposed to scale complex fraud operations and how abuse of legitimate authentication flows can enable widespread account takeover. Stopping EvilTokens required cross-industry cooperation and legal action, underscoring the importance of coordinated responses to sophisticated cybercrime services.
Key Facts
- Platform name: EvilTokens
- Announced disruption: Microsoft-led industry operation (announced Tuesday)
- Accounts compromised: 12,000 Microsoft accounts
- Organizations affected: About 10,000 organizations
- Launch / marketing: Introduced over a Telegram channel in February
Microsoft announced it coordinated an industry-wide disruption of EvilTokens, a paid cybercrime platform that used an AI-style chatbot to streamline mass email account compromises. The service, which appeared in a Telegram channel in February, charged an upfront fee of $1,500 plus $500 per month thereafter and bundled many steps attackers typically perform into a single offering.
According to Microsoft, EvilTokens automated inbox analysis, helped attackers identify high-value targets and trusted relationships, and could draft convincing follow-up messages impersonating contacts to induce victims to transfer funds. The company said customers of the platform successfully compromised roughly 12,000 Microsoft accounts tied to about 10,000 organizations, with the largest concentration in the United States and additional victims in Canada, the UK, Australia, India, and France.
Victim organizations spanned multiple sectors, including wholesale distribution, construction, financial services, real estate, higher education, and healthcare. SpyCloud, a security firm that partnered with Microsoft in the disruption, has provided further victim details. Microsoft also said the platform leveraged a legitimate OAuth flow known as device code authentication — a method intended for devices with limited input capabilities — to obtain access to accounts.
Using legal processes and a network of partners, Microsoft said it seized 50 websites and 150 domains tied to EvilTokens. The UK Metropolitan Police Service arrested two men on suspicion of offenses connected to the platform as part of the operation. Microsoft framed the action as an example of how coordinated industry and law-enforcement efforts can disrupt services that weaponize automation and legitimate authentication mechanisms for fraud.
Keep Reading

Dyson’s most overengineered gadget may have a waterproofing problem

Toyota orders workers to train humanoid robots but says humans won't be replaced

Lawsuit demands OpenAI pay for new school after ChatGPT used in shooting
