Microsoft disrupts EvilTokens, an AI-assisted email fraud service
The service analyzed stolen inboxes to map relationships and suggest fraud targets; Microsoft says more than 12,000 accounts were compromised.
OddBrief EditorialAI-assisted, human-reviewed
InternetKey facts
- Accounts
- More than 12,000 compromised inboxes, according to Microsoft
- Organizations
- More than 10,000 affected worldwide, according to Microsoft
- Disruption
- 50 websites seized and more than 150 domains disabled
- Pricing
- $1,500 entry and $500 recurring subscription, according to Microsoft
- Investigation
- Two UK suspects arrested and released on police bail
Microsoft says it has disrupted EvilTokens, a subscription cybercrime service that paired stolen email access with an AI chatbot for planning fraud. The company says the operation was linked to more than 12,000 compromised inboxes at over 10,000 organizations within months of its February launch. Those figures come from Microsoft's investigation, not a full public census of victims.
The inbox became the targeting engine
According to Microsoft's Digital Crimes Unit, EvilTokens used a device-code sign-in trick to get access to Microsoft accounts. Victims entered a code on a genuine Microsoft sign-in page, so handing over access could feel like completing an ordinary authentication step. A password reset alone might not end an intruder's access if sessions and tokens remained valid.
Once inside, the service's AI tools could summarize and translate email, find financial conversations, identify people with payment authority and suggest whom to impersonate. The dangerous step was not just generating polished scam text. It was turning a private mailbox into a map of trusted relationships and likely payment opportunities.
Microsoft says the service was sold through Telegram for a $1,500 entry fee and $500 recurring subscription. Its investigators also found evidence that AI helped the operators build parts of the platform. That combination put account compromise, analysis and fraud preparation behind a commercial interface.
A coordinated takedown, with limits
Microsoft says it seized 50 websites and disabled more than 150 associated domains after a court-authorized operation with Health-ISAC and several partners. The Metropolitan Police arrested two men in the United Kingdom on September 11 on suspicion of offenses connected with the alleged service. They were released on police bail while the investigation continues; an arrest is not a finding of guilt.
The disruption takes away infrastructure, but it cannot erase inbox contents already copied or guarantee that users of the service have stopped. Microsoft says it notified affected customers and helped with account remediation. It has not published a complete accounting of financial losses or a verified count of people defrauded, so the scale of compromise should not be read as the scale of successful fraud.
What changes for defenders
The case suggests that the time between a mailbox takeover and a tailored payment request may be shrinking. Organizations need to treat account access as both an identity problem and an information leak. Revoking sessions and tokens after a suspected compromise matters alongside password changes.
Payment changes also deserve confirmation through an independently known channel, especially when an email appears to come from a familiar colleague or supplier. Microsoft's lesson is wider than this one takedown: AI can help a criminal understand whom to deceive, while the decisive opening may still be a human approving an unexpected sign-in.
Sources
- Disrupting EvilTokens: The AI Chatbot Built for CybercrimeMicrosoft Digital Crimes Unitprimary source


