Microsoft disrupts AI-assisted platform that compromised 12,000 accounts

by | Oct 7, 2026 | Technology

Microsoft disrupts AI-assisted platform that compromised 12,000 accounts

Microsoft announced the disruption of EvilTokens, a subscription-based cybercriminal platform that leveraged artificial intelligence to facilitate large-scale email account compromises. The platform, which launched over Telegram in February and operated through a paid subscription model, targeted Microsoft accounts belonging to organizations across multiple sectors including financial services, healthcare, education, real estate, and construction.

The EvilTokens service provided an integrated toolkit designed to streamline the account compromise process. At its core was an AI chatbot that analyzed victim inboxes to identify trusted business relationships, payment authorization patterns, and organizational hierarchies. The platform then used this intelligence to recommend fraud strategies and generate convincing impersonation messages targeting specific employees likely to authorize financial transfers. Users of the platform successfully compromised 12,000 accounts across 10,000 organizations, with the heaviest concentrations in the United States, Canada, the United Kingdom, Australia, India, and France.

The attack methodology exploited a legitimate authentication mechanism called device code authentication, typically designed for devices with limited input capabilities. EvilTokens automated the delivery of malicious emails containing hidden scripts that interacted with Microsoft’s identity provider in real time. When users clicked malicious links, they were directed to pages that generated device codes, which users unknowingly entered into official Microsoft login portals, granting attackers access.

Microsoft coordinated an industry-wide disruption effort that resulted in the seizure of 50 websites and 150 additional domains associated with the operation. The United Kingdom’s Metropolitan Police Service arrested two individuals in connection with the scheme. Microsoft emphasized that organizations should assume compromised inboxes may be analyzed within minutes rather than days, recommending strong identity protections, continuous monitoring, and independent verification of sensitive requests through separate channels.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI