Microsoft disrupts AI-assisted platform that compromised 12,000 accounts

by | Sep 30, 2026 | Technology

Microsoft disrupts AI-assisted platform that compromised 12,000 accounts

Microsoft announced the disruption of EvilTokens, a subscription-based cybercriminal platform that leveraged artificial intelligence to streamline large-scale account compromises. The platform, which launched in February via a Telegram channel, charged an initial fee of $1,500 with recurring monthly charges of $500 for access to its services.

The EvilTokens platform provided an integrated toolkit designed to automate and accelerate multiple stages of account compromise operations. The system included an AI-powered chatbot capable of analyzing victim inboxes to identify trusted relationships, payment authorization patterns, and organizational hierarchies. Using this intelligence, the platform recommended fraud strategies and generated realistic impersonation messages tailored to deceive company employees into authorizing unauthorized fund transfers to attacker-controlled accounts.

During its operational period, EvilTokens users compromised approximately 12,000 customer accounts belonging to 10,000 organizations distributed globally, with the heaviest concentration in the United States. Other significantly affected countries included Canada, the UK, Australia, India, and France. Targeted sectors encompassed wholesale distribution, construction, financial services, real estate, higher education, and healthcare. The compromise method exploited a legitimate OAuth authentication process called device code authentication, which is typically designed for input-limited devices like televisions.

The technical attack chain involved sending phishing emails containing malicious links that directed victims to pages running hidden automation scripts. These scripts interacted with Microsoft Entra identity providers to generate device codes. Victims were then instructed to enter these codes into the official Microsoft device login portal, allowing attackers to gain account access while bypassing traditional detection methods through sophisticated backend automation logic.

In response, Microsoft executed a coordinated industry-wide disruption operation that resulted in seizing 50 websites and 150 additional domains supporting the platform. The UK’s Metropolitan Police Service arrested two individuals in connection with the operation. Microsoft emphasized that the incident underscores the accelerated threat landscape enabled by AI tools and recommended that organizations implement strong identity protections, enhanced monitoring, and independent verification of sensitive requests through alternative communication channels.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI