Microsoft disrupts AI-assisted platform that compromised 12,000 accounts

by | Sep 29, 2026 | Technology

Microsoft disrupts AI-assisted platform that compromised 12,000 accounts

Microsoft announced the disruption of EvilTokens, a subscription-based cyber attack platform that leveraged artificial intelligence to facilitate mass account compromises. The platform charged an initial fee of $1,500 followed by recurring monthly charges of $500 and was introduced through a Telegram channel in February. Over a span of several months, users of EvilTokens successfully compromised 12,000 Microsoft accounts belonging to 10,000 organizations globally, with concentrations in the United States, Canada, the United Kingdom, Australia, India, and France.

The platform operated as a comprehensive attack tool that streamlined multiple stages of account compromise. At its core was an AI-powered chatbot designed to analyze victim inboxes and identify valuable targets based on organizational hierarchies, payment authorizations, and trusted relationships. The system could recommend fraud strategies and generate realistic impersonation messages to convince employees to transfer funds to attacker-controlled accounts. Targeted sectors included wholesale distribution, construction, financial services, real estate, higher education, and healthcare.

The attack methodology exploited device code authentication, a legitimate OAuth process intended for devices with limited input capabilities such as televisions. Victims received phishing emails containing malicious links that directed them to pages running hidden automation scripts. These scripts interacted with Microsoft Entra identity providers to generate device codes, which users were then instructed to enter into official Microsoft login portals, unknowingly granting attackers account access.

The platform’s dashboard allowed attackers to customize lures for specific organizations while automating much of the technical infrastructure. Analysis capabilities enabled the system to process thousands of compromised emails simultaneously, identifying financial decision-makers and crafting convincing scenarios for fund transfers. Microsoft noted that the AI-assisted approach dramatically reduced the time attackers traditionally needed to understand organizational structures and relationships.

Microsoft, working with industry partners and using legal processes, seized 50 websites and 150 additional domains associated with the operation. The United Kingdom’s Metropolitan Police Service arrested two individuals in connection with the platform. Microsoft emphasized that organizations should assume compromised inboxes could be fully analyzed within minutes and recommended independent verification of financial requests through separate communication channels.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI