Safety & Security

Microsoft Disrupts EvilTokens, AI Chatbot Platform Behind 12,000 Account Hacks

Microsoft led an industry-wide takedown of EvilTokens, a $1,500-upfront subscription platform whose AI chatbot analyzed victims' inboxes and drafted fraud emails, hitting 12,000 accounts.

Microsoft disrupts AI-assisted platform that compromised 12,000 accounts
Microsoft disrupts AI-assisted platform that compromised 12,000 accountsElogia Marketing4eCommerce / Openverse
By Marcus Bennett3 min read

Updated

Why it matters

  • Microsoft said Tuesday it led an industry-wide disruption of EvilTokens, which compromised 12,000 Microsoft accounts over a few months.
  • EvilTokens launched via Telegram in February, charging $1,500 upfront and $500 per month.
  • The platform's AI chatbot analyzed victims' inboxes, identified high-value fraud opportunities, and drafted impersonation emails.

Microsoft said Tuesday that it led an industry-wide disruption of a subscription-based scam platform that used an AI chatbot to compromise 12,000 Microsoft accounts over a few-month span.

The platform, named EvilTokens, appeared in February on a Telegram channel. It charged an initial $1,500 fee plus a recurring $500 monthly charge. For that price, customers got a single service that streamlined most of the steps required to compromise email accounts at scale.

The operation marks an early, concrete case of generative AI being productized specifically for cybercrime — sold as a service with pricing, onboarding, and automated workflows. That matters beyond Microsoft's own user base: the same tooling that drafts marketing copy or code can draft convincing impersonation emails, and it lowers the skill barrier for running large-scale fraud campaigns.

Minutes, not days

The core of the service was not the account access itself but what came after. An AI-style chatbot analyzed each victim's inbox and guided criminals toward the most profitable attack path.

"While EvilTokens helped cybercriminals access email accounts, at the center of the service was an AI-style chatbot that could analyze a victim's inbox and help criminals identify trusted relationships, payment authorizations, and sensitive responsibilities, as well as other circumstances where fraud was most likely to succeed," Microsoft said in its announcement.

The company continued: "The platform could even recommend fraud strategies, including drafting messages that impersonated trusted contacts to help criminals trick victims into taking action."

In practice, the platform took over the labor-intensive stages of business email compromise. Once inside an account, it analyzed inboxes, selected targets that promised the biggest potential payouts, and drafted follow-up emails carrying realistic ruses for tricking company employees into transferring funds to attacker-controlled accounts.

That pipeline collapses work that traditionally took attackers days of manual inbox reconnaissance and careful email drafting into a process measured in minutes. The target-selection step is notable: rather than blasting every contact, the system ranked victims by financial exposure — payment authorizations, trusted relationships, sensitive responsibilities — before a single fraudulent message was sent.

Why the disruption matters

EvilTokens operated on a straightforward commercial model: a $1,500 entry fee and $500 per month afterward. That subscription structure signals demand. Criminals were willing to pay recurring SaaS-style fees for AI-assisted account compromise, which suggests the platform generated returns for its customers.

The 12,000 compromised Microsoft accounts fell within a span of just a few months, according to the company. Microsoft described the takedown as an industry-wide effort rather than a unilateral action, indicating coordination across the security ecosystem to dismantle the platform's infrastructure.

For defenders, the case defines the threat model security teams now face: AI-driven reconnaissance inside compromised mailboxes, contextually credible impersonation at scale, and automated prioritization of high-value targets. Expect threat intelligence teams to treat AI-assisted fraud platforms as a distinct category going forward, and Tuesday's disruption is unlikely to be the last one Microsoft attempts.

Original: blogs.microsoft.com

Share this article:

More from Marcus Bennett

Marcus Bennett

Show full bio

Senior reporter covering consumer brands and retail at AI In Context.

108 articles

Related articles

  1. How an OpenAI Investigator's Own Phone Helped Bust an AI Task Scam
  2. OpenAI Maps the Anatomy of AI-Enabled Romance Scams
  3. OpenAI Bans Korean-Language Accounts Tied to Malware Development

Next article »