Security

Microsoft Disrupts EvilTokens AI Chatbot Built for Email Fraud

The cybercrime platform used AI to analyze stolen inboxes, identify targets, and automate business email compromise attacks at scale.

Omega Editorial· September 22, 2026· 3 min read

Microsoft has taken down EvilTokens, a cybercrime-as-a-service platform that weaponized artificial intelligence to automate business email compromise attacks from initial access through financial fraud execution. The disruption, detailed by Microsoft, represents the first major enforcement action against an end-to-end AI-enabled cybercrime operation.

Launched in February 2026, EvilTokens quickly compromised more than 12,000 email inboxes across 10,000 organizations worldwide before its infrastructure was seized. The service combined stolen account access with an AI chatbot that could analyze victims' email histories, map organizational relationships, and recommend specific fraud strategies—fundamentally changing the speed and sophistication of business email compromise attacks.

How the platform weaponized AI

EvilTokens first helped criminals gain email access through device-code phishing attacks that tricked victims into completing legitimate Microsoft authentication flows. Once inside an account, the platform's AI tools took over tasks that traditionally required significant manual effort and expertise.

The chatbot could summarize and translate emails, identify financial conversations, map organizational hierarchies, and surface trusted relationships. Preset prompts offered to locate wire-transfer discussions, identify employees with payment authority, find vendor invoices, and determine which contacts would be most effective to impersonate. The system then recommended fraud strategies and could draft convincing messages mimicking trusted colleagues or business partners.

Cybercriminals accessed these capabilities through a Telegram-based subscription service charging a $1,500 initiation fee and $500 monthly recurring payments. The platform included customer support, management dashboards, and tools designed to guide users from initial account access toward financial exploitation.

Global disruption effort

Microsoft's Digital Crimes Unit coordinated with Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs to dismantle the operation. Working under authorization from the U.S. District Court for the Eastern District of Virginia, the coalition seized 50 websites operating the service and disabled more than 150 supporting domains.

The Metropolitan Police Service's cybercrime team in the United Kingdom arrested two men, aged 32 and 38, on September 11, 2026, in connection with the alleged operation. Both were released on bail pending further investigation.

Investigators determined that large portions of EvilTokens were "vibe coded"—built with AI assistance—and drew capabilities from multiple AI models. Microsoft's own investigators used AI-powered analysis tools to accelerate evidence examination and infrastructure mapping during the takedown.

Why it matters

EvilTokens demonstrates how AI is collapsing the timeline between account compromise and sophisticated fraud. Organizations can no longer assume they have days to detect and respond to compromised email accounts—criminals with AI assistance can understand an inbox's contents, relationships, and exploitation opportunities within minutes. This shift requires organizations to implement stronger identity protections, assume breach when unusual requests occur, and independently verify any payment changes or fund transfers through trusted secondary channels outside email.

The disruption marks Microsoft's 40th court-authorized action against cyber threats and its first targeting an AI-enabled cybercrime service. Victims spanned wholesale distribution, construction, financial services, real estate, higher education, and healthcare sectors, with the highest concentrations in the United States, Canada, the United Kingdom, Australia, India, and France.

These details were first reported by Microsoft in a blog post on its On the Issues site.

#business email compromise#ai security#cybercrime#microsoft#threat intelligence#fraud prevention

This is an original analysis by the Omega editorial team. Source reporting: AI Watch.

Want systems like this working for your business?

Book a Call

More in Security

Security· 3 min read

AI Deployment Accelerates Amid Rising Public Anxiety and Regulatory Pushback

From military near-misses to data center battles, artificial intelligence is reshaping communities faster than governments can respond.

Via AI Watch · Sep 22, 2026
Security· 3 min read

Microsoft Dismantles AI-Powered Cybercrime Platform EvilTokens

Court-authorized takedown seized 50 websites after hackers used AI chatbots to analyze stolen emails and automate business fraud at scale.

Via AI Watch · Sep 22, 2026
Security· 3 min read

CLOSEDQUORUM malware delegates C2 decisions to four AI models

Cisco Talos discovers Windows implant that uses LLM voting to autonomously select its next actions without human operator commands.

Via AI Watch · Sep 22, 2026