Microsoft disrupts EvilTokens AI scam platform that hit 12,000 accounts

Microsoft disrupts EvilTokens AI scam platform that hit 12,000 accounts

Microsoft said Tuesday that it led an industry-wide disruption of EvilTokens, a subscription-based scam platform that used an AI chatbot to help criminals compromise Microsoft accounts on a large scale. The platform was introduced on a Telegram channel in February, charging subscribers an initial $1,500 fee plus a recurring $500 a month after that. For that price, EvilTokens automated most of the work of breaking into email accounts in bulk: it helped customers get in, then analyzed the compromised inboxes, picked out targets likely to yield the biggest payouts, and drafted follow-up emails impersonating trusted contacts to trick company employees into wiring money to attacker-controlled accounts. Microsoft described an AI-style chatbot at the center of the service that could read a victim's inbox to identify trusted relationships, payment authorizations, and sensitive responsibilities, then recommend fraud strategies, including drafted messages, for the circumstances most likely to succeed. Users of EvilTokens compromised 12,000 customer accounts belonging to 10,000 organizations worldwide, with the heaviest concentration in the US, followed by Canada, the UK, Australia, India, and France. Victim organizations spanned wholesale distribution, construction, financial services, real estate, higher education, and healthcare. Working through a legal process and a network of partners, Microsoft seized 50 websites and a further 150 domains used to run EvilTokens, and the UK's Metropolitan Police Service arrested two men, who were not named, on suspicion of offenses connected to the platform. The account takeovers themselves relied on a legitimate OAuth mechanism called device code authentication, built for TVs and other devices too input-constrained for a normal login screen: the device displays a code that the user enters into a browser on a separate device, which then gets authenticated. Security firm SpyCloud assisted in the disruption operation and has published further detail on the victims.

Key facts

  • EvilTokens, launched via Telegram in February, charged a $1,500 initial fee plus $500 a month and compromised 12,000 Microsoft accounts at 10,000 organizations worldwide.
  • An AI-style chatbot at the platform's core analyzed victims' inboxes to find trusted relationships and payment authorizations, then drafted impersonation emails to trick employees into wiring funds.
  • The US had the highest concentration of victims, followed by Canada, the UK, Australia, India, and France, across sectors from construction to healthcare.
  • Microsoft seized 50 websites and 150 more domains used to run the platform, and the UK's Metropolitan Police Service arrested two unnamed men.
  • The account compromises exploited device code authentication, a legitimate OAuth flow meant for TVs and other input-constrained devices.

Why it matters

This is a rare public look at how far AI-assisted fraud tooling has moved into an as-a-service business model. EvilTokens was not just a phishing kit; it was a subscription product with recurring billing, and its selling point was an AI chatbot that did the analytical work of picking targets and writing convincing impersonation emails, work that previously required a skilled human operator per victim.

Who it affects

Directly, the 10,000 organizations whose Microsoft accounts were among the 12,000 compromised, concentrated in the US and also present in Canada, the UK, Australia, India, and France, across wholesale distribution, construction, financial services, real estate, higher education, and healthcare. More broadly, it affects any organization relying on OAuth device code authentication as an attack surface, and Microsoft and its disruption partners, including SpyCloud, who now carry the legal and operational work of the takedown.

How to use it

Organizations should treat device code authentication flows as a specific phishing vector: train staff to be wary of prompts to enter a code shown on one device into a browser on another, since that is precisely the legitimate-looking mechanism EvilTokens abused. Finance and accounts-payable staff, the likely targets of the impersonation emails the platform drafted, are the group most worth briefing on this specific ruse.

How solid is it

The account comes directly from Microsoft, the party that led the disruption, corroborated by an actual takedown: 50 websites and 150 domains seized, and two arrests by the UK's Metropolitan Police Service. SpyCloud, a named security firm, assisted and has published additional victim detail. The article does not give a total financial loss figure, name the two men arrested, identify the AI model or vendor behind the chatbot, or state the year for the 'Tuesday' announcement or the February launch.

Risks and caveats

Key specifics are missing from the public account: no dollar figure for losses, no names for the two men arrested, and no identification of which AI system powered the chatbot. The timeline is also loose, described only as 'a few-month span' between the February launch and the disruption, so exact duration and dates are not established.

“While EvilTokens helped cybercriminals access email accounts, at the center of the service was an AI-style chatbot that could analyze a victim's inbox and help criminals identify trusted relationships, payment authorizations, and sensitive responsibilities, as well as other circumstances where fraud was most likely to succeed”

— Microsoft