Microsoft disrupts AI-assisted platform that compromised 12,000 accounts

by | Oct 3, 2026 | Technology

Microsoft disrupts AI-assisted platform that compromised 12,000 accounts

Microsoft announced the disruption of EvilTokens, a subscription-based cyber crime platform that leveraged artificial intelligence to facilitate mass account compromises. The platform, which launched in February through a Telegram channel, charged an initial fee of $1,500 followed by monthly recurring charges of $500. Over a span of several months, the service enabled attackers to compromise approximately 12,000 Microsoft accounts belonging to roughly 10,000 organizations globally.

The platform operated as an end-to-end solution designed to streamline the process of compromising email accounts at scale. At its core was an AI-powered chatbot capable of analyzing victims’ inboxes to identify trusted relationships, payment authorization processes, and other vulnerabilities that could be exploited for financial fraud. The system provided recommendations for fraud strategies and could even draft impersonation messages to deceive employees into transferring funds to attacker-controlled accounts. Affected organizations spanned multiple sectors including wholesale distribution, construction, financial services, real estate, higher education, and healthcare, with the highest concentration of victims in the United States followed by Canada, the UK, Australia, India, and France.

The attack methodology exploited a legitimate OAuth authentication mechanism known as device code authentication, typically designed for devices with limited input capabilities. Attackers used malicious emails to redirect users to webpages containing hidden automation scripts that generated device codes for unauthorized device enrollment. Users were then prompted to enter these codes into Microsoft’s official device login portal, granting attackers account access. The platform’s backend automation minimized detection by traditional security measures.

Law enforcement and technology partners coordinated to dismantle the operation, resulting in the seizure of 50 websites and 150 additional domains. The UK’s Metropolitan Police Service made arrests of two individuals suspected of involvement. Microsoft emphasized that organizations should assume compromised inboxes may be fully analyzed by attackers within minutes rather than days, recommending independent verification of payment and transaction requests through separate communication channels alongside strong identity protections and continuous monitoring.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI