September 28, 2026
Microsoft-discontinues-AI-assisted-platform-that-compromised-12000-accounts.jpg

Microsoft said Tuesday that it led an industry-wide disruption of a subscription-based scam platform that used an artificial intelligence chatbot to compromise 12,000 Microsoft accounts over the span of a few months.

Called EvilTokens, the platform was introduced through a Telegram channel in February and charged an initial fee of $1,500 and a recurring charge of $500 each month after that. EvilTokens provided a unique service to simplify most of the steps required to compromise large numbers of email accounts. From there, the platform helped clients analyze inboxes, select targets that would provide the highest potential payouts, and compose follow-up emails that provided realistic ruses to trick company employees into transferring funds to accounts controlled by attackers.

Minutes, not days

“While EvilTokens helped cybercriminals access email accounts, at the heart of the service was an AI-style chatbot that could analyze a victim’s inbox and help criminals identify trust relationships, sensitive payment authorizations and responsibilities, as well as other circumstances in which fraud was more likely to succeed,” Microsoft said. “The platform could even recommend fraud strategies, including writing messages posing as trusted contacts to help criminals trick victims into taking action.”

Microsoft said EvilToken users compromised 12,000 customer accounts belonging to 10,000 organizations worldwide, with the largest concentration of them in the United States. The countries with the next highest numbers were Canada, the United Kingdom, Australia, India and France. Victim organizations included wholesale distribution, construction, financial services, real estate, higher education, and healthcare. SpyCloud, a security company that assisted in the disruption operation, has more details about the victims here.

Using a legal process and a network of partners, Microsoft seized 50 websites and 150 most used domains to operate EvilTokens. The United Kingdom’s Metropolitan Police Service has arrested two men on suspicion of offenses allegedly linked to the criminal platform.

The compromised accounts were achieved through a legitimate OAuth process known as device code authentication. This form of authentication is designed for TVs and devices with restricted input, that is, those that lack the interface to perform normal login processes. In this model, the device being logged in presents a code and instructs the user to enter it into a browser on a separate device. The new device is then authenticated.

Avatar photo
Written by

Jhon Smith

Info Vitalis is a content writer specializing in creating clear, concise, and engaging articles. With experience in health, lifestyle, technology, and current events, Info Vitalis aims to provide readers with useful and easy-to-understand information.

Leave a Reply

Your email address will not be published. Required fields are marked *