Skip to content
OddBrief
Internet2 minTraced to the primary source

Microsoft disrupts EvilTokens, an AI-assisted email fraud service

The service analyzed stolen inboxes to map relationships and suggest fraud targets; Microsoft says more than 12,000 accounts were compromised.

AI-assisted, human-reviewed

Abstract blue Microsoft graphic with bright cyan gradients, rectangular blocks and thin white dividing lines.Internet
Microsoft Digital Crimes Unit / official blog artwork

Key facts

Accounts
More than 12,000 compromised inboxes, according to Microsoft
Organizations
More than 10,000 affected worldwide, according to Microsoft
Disruption
50 websites seized and more than 150 domains disabled
Pricing
$1,500 entry and $500 recurring subscription, according to Microsoft
Investigation
Two UK suspects arrested and released on police bail

Microsoft says it has disrupted EvilTokens, a subscription cybercrime service that paired stolen email access with an AI chatbot for planning fraud. The company says the operation was linked to more than 12,000 compromised inboxes at over 10,000 organizations within months of its February launch. Those figures come from Microsoft's investigation, not a full public census of victims.

The inbox became the targeting engine

According to Microsoft's Digital Crimes Unit, EvilTokens used a device-code sign-in trick to get access to Microsoft accounts. Victims entered a code on a genuine Microsoft sign-in page, so handing over access could feel like completing an ordinary authentication step. A password reset alone might not end an intruder's access if sessions and tokens remained valid.

Once inside, the service's AI tools could summarize and translate email, find financial conversations, identify people with payment authority and suggest whom to impersonate. The dangerous step was not just generating polished scam text. It was turning a private mailbox into a map of trusted relationships and likely payment opportunities.

Microsoft says the service was sold through Telegram for a $1,500 entry fee and $500 recurring subscription. Its investigators also found evidence that AI helped the operators build parts of the platform. That combination put account compromise, analysis and fraud preparation behind a commercial interface.

A coordinated takedown, with limits

Microsoft says it seized 50 websites and disabled more than 150 associated domains after a court-authorized operation with Health-ISAC and several partners. The Metropolitan Police arrested two men in the United Kingdom on September 11 on suspicion of offenses connected with the alleged service. They were released on police bail while the investigation continues; an arrest is not a finding of guilt.

The disruption takes away infrastructure, but it cannot erase inbox contents already copied or guarantee that users of the service have stopped. Microsoft says it notified affected customers and helped with account remediation. It has not published a complete accounting of financial losses or a verified count of people defrauded, so the scale of compromise should not be read as the scale of successful fraud.

What changes for defenders

The case suggests that the time between a mailbox takeover and a tailored payment request may be shrinking. Organizations need to treat account access as both an identity problem and an information leak. Revoking sessions and tokens after a suspected compromise matters alongside password changes.

Payment changes also deserve confirmation through an independently known channel, especially when an email appears to come from a familiar colleague or supplier. Microsoft's lesson is wider than this one takedown: AI can help a criminal understand whom to deceive, while the decisive opening may still be a human approving an unexpected sign-in.

Sources

  1. Disrupting EvilTokens: The AI Chatbot Built for Cybercrime
    Microsoft Digital Crimes Unitprimary source

Related reading