Today's AI/ML headlines are brought to you by ThreatPerspective

Digital Event Horizon

Microsoft Leads Industry-Wide Disruption of AI-Assisted Scam Platform that Compromised 12,000 Microsoft Accounts


Microsoft has disrupted a subscription-based scam platform that compromised 12,000 Microsoft accounts, using an AI chatbot to streamline the process and reduce the time it takes for attackers to identify and exploit vulnerabilities. The platform, known as EvilTokens, was shut down after Microsoft and its partners took action to seize domains and arrest those suspected of being involved.

  • Microsoft disrupted a subscription-based scam platform called EvilTokens, which compromised 12,000 Microsoft accounts using an AI chatbot.
  • The platform provided a service to streamline compromising email accounts in large numbers, including analyzing inboxes and drafting follow-up emails.
  • The AI chatbot played a central role in identifying trusted relationships, payment authorizations, and sensitive responsibilities to help criminals succeed.
  • Microsoft seized 50 websites and 150 domains used to operate EvilTokens and arrested two men on suspicion of offenses connected to the crime platform.
  • The platform used a legitimate OAuth process to automate the sending of spam and interact with users' Microsoft identity providers in real time.
  • EvilTokens represents a major shift in the mass compromise and post-compromise of accounts, with AI-assisted tools greatly reducing the time for attackers to assemble an organization's management chart.
  • Microsoft's actions highlight the importance of industry-wide cooperation in the fight against cybercrime and the risks associated with the misuse of AI technology.



  • Microsoft has made a significant move in the fight against cybercrime by leading an industry-wide disruption of a subscription-based scam platform that used an AI chatbot to compromise 12,000 Microsoft accounts over a few-month span. The platform, known as EvilTokens, was introduced over a Telegram channel in February and charged an initial $1,500 fee and a recurring $500 charge each month after that.

    EvilTokens provided a single service for streamlining most steps required to compromise email accounts in large numbers. From there, the platform helped customers analyze inboxes, select targets that would provide the biggest potential payouts, and draft follow-up emails that provided realistic ruses for tricking company employees into transferring funds to attacker-controlled accounts. The platform's AI-style chatbot played a central role in this process, analyzing a victim's inbox and helping criminals identify trusted relationships, payment authorizations, and sensitive responsibilities, as well as other circumstances where fraud was most likely to succeed.

    The platform could even recommend fraud strategies, including drafting messages that impersonated trusted contacts to help criminals trick victims into taking action. Using a legal process and a network of partners, Microsoft seized 50 websites and 150 more domains used to operate EvilTokens. The UK's Metropolitan Police Service arrested two men on suspicion of offenses allegedly connected to the crime platform.

    Account compromises were achieved through a legitimate OAuth process known as device code authentication, which is designed for TVs and input-constrained devices. EvilTokens provided customers with a platform that automated the sending of large numbers of spam. Users who clicked on malicious links or attachments in the emails were directed to a webpage running a hidden automation script that interacts with the user's Microsoft identity provider in real time to generate a code for enrolling a device belonging to the attacker.

    The platform allowed the process to work end to end, from the generation of dynamic device codes to post-compromise activities. A dashboard allowed users to tailor lures to the profiles of the organizations they targeted. The platform largely automated the rest of the attack process as well. EvilTokens analyzed 5,000 compromised emails at a time, using AI to identify employees authorized to disburse large sums of money, the managers these employees reported to, and convincing scenarios under which the manager or others could persuade the employees to transfer money into what turned out to be attacker-controlled accounts.

    Microsoft said that EvilTokens represents a major shift in the mass compromise and post-compromise of accounts. Normally, it took time for attackers to sift through thousands of emails to assemble the organization’s management chart, suppliers, customers, and other relationships with third parties. That burden is greatly reduced with AI-assisted tools. For organizations, the lesson is: assume that once an inbox is compromised, criminals may understand its contents in minutes, not days.

    Strong identity protections and monitoring remain essential, but organizations should also independently verify requests to change payment information, redirect funds, or approve unusual transactions through a trusted second channel. Microsoft's actions demonstrate the importance of collaboration and industry-wide cooperation in the fight against cybercrime, and serve as a stark reminder of the risks associated with the misuse of AI technology.



    Related Information:
  • https://www.digitaleventhorizon.com/articles/Microsoft-Leads-Industry-Wide-Disruption-of-AI-Assisted-Scam-Platform-that-Compromised-12000-Microsoft-Accounts-deh.shtml

  • https://arstechnica.com/security/2026/09/microsoft-disrupts-ai-assisted-platform-that-compromised-12000/


  • Published: Tue Sep 22 16:16:54 2026 by llama3.2 3B Q4_K_M











    © Digital Event Horizon . All rights reserved.

    Privacy | Terms of Use | Contact Us