Microsoft Dismantles AI-Powered Cybercrime Platform EvilTokens
Court-authorized takedown seized 50 websites after hackers used AI chatbots to analyze stolen emails and automate business fraud at scale.

Microsoft's Digital Crimes Unit has dismantled a sophisticated cybercrime operation that weaponized artificial intelligence to automate email fraud, marking one of the clearest examples yet of how existing AI tools are enabling financial crime at industrial scale.
The company obtained authorization from the U.S. District Court for the Eastern District of Virginia to seize infrastructure tied to EvilTokens, a subscription-based phishing platform that combined device-code phishing tactics with AI-powered inbox analysis. Working with industry partners and law enforcement, Microsoft seized 50 websites operating the service and disabled more than 150 additional domains. British authorities arrested two men, ages 32 and 38, earlier this month in connection with the platform.
Why it matters
While policy debates focus on speculative AI risks, financially motivated hackers are already deploying current-generation AI tools to compress attack timelines from days to hours. EvilTokens demonstrates how AI lowers barriers on both sides of cybercrime: helping criminals build malicious infrastructure faster while enabling less-sophisticated buyers to execute complex fraud schemes they couldn't manage manually.
How the platform operated
EvilTokens launched in February as a phishing-as-a-service operation charging hackers a $1,500 initiation fee plus $500 monthly. Subscribers received personalized phishing lures disguised as construction bids, partnership agreements, benefits notices, and password warnings.
The platform's innovation was integrating an AI chatbot that analyzed compromised email inboxes to map organizational hierarchies, identify trusted relationships, and surface payment-related conversations. This AI component condensed reconnaissance work that typically requires days of manual review into hours of automated analysis, helping attackers determine who controlled finances, whom they trusted, and whom to impersonate for maximum impact.
Once hackers gained access through device-code phishing—tricking victims into entering codes on Microsoft's legitimate sign-in page—they could deploy the AI tools to extract actionable intelligence and craft convincing follow-on fraud attempts using information harvested from the victim's own correspondence.
Scale of compromise
Microsoft estimates EvilTokens compromised more than 12,000 email inboxes across 10,000 organizations spanning construction, financial services, real estate, higher education, and healthcare sectors. The highest victim concentrations appeared in the United States, Canada, the United Kingdom, Australia, India, and France. Coinbase, which assisted in the investigation, traced approximately $1.1 million in revenue to the platform.
Microsoft also discovered that "large portions" of EvilTokens itself were "vibe coded"—built using AI development tools—illustrating how AI accelerated both the platform's creation and its operational capabilities.
The company began publicly warning customers about EvilTokens tactics in April after researchers first observed the service successfully compromising Microsoft accounts in February. A Microsoft spokesperson noted the takedown represented "a relatively accelerated operation from initiation to execution" once the full scale and sophistication became apparent.
Law enforcement agencies are conducting ongoing investigations into the platform, according to Microsoft.
These details were first reported by Axios.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call