Security

Microsoft Takes Down EvilTokens AI Fraud Platform

The subscription service used AI to analyze 12,000 compromised inboxes and automate business email compromise attacks at scale.

Omega Editorial· September 22, 2026· 3 min read

Microsoft announced it has disrupted a sophisticated cybercrime platform that leveraged artificial intelligence to automate business email compromise attacks, according to details first reported by Ars Technica. The operation compromised 12,000 Microsoft accounts across 10,000 organizations worldwide within months.

The platform, called EvilTokens, operated as a subscription service launched via Telegram in February 2026. Customers paid an initial $1,500 fee plus $500 monthly to access an end-to-end system that streamlined mass account compromise and subsequent fraud operations.

How the platform worked

EvilTokens exploited OAuth device code authentication, a legitimate Microsoft process designed for input-constrained devices like smart TVs. The platform automated spam campaigns that directed victims to webpages running hidden scripts. These scripts interacted with Microsoft Entra identity providers in real time to generate device enrollment codes.

When users followed instructions to enter these codes into Microsoft's official device login portal, attackers gained persistent access to their accounts. The platform's Node.js backend logic evaded traditional detection methods by generating dynamic device codes rather than using static patterns.

AI-powered fraud at scale

The platform's core innovation was an AI chatbot that analyzed compromised inboxes to identify high-value fraud opportunities. The system could process 5,000 emails at a time, mapping organizational hierarchies, identifying employees authorized to transfer funds, and pinpointing their managers and trusted contacts.

The AI then recommended fraud strategies and drafted convincing impersonation messages designed to trick employees into transferring money to attacker-controlled accounts. This automation dramatically compressed timelines that previously required manual analysis.

Why it matters

EvilTokens represents a fundamental shift in cybercrime economics. Traditional business email compromise required attackers to manually sift through thousands of emails over days or weeks. AI automation reduces that timeline to minutes, allowing criminals to exploit compromised accounts before organizations can detect and respond to breaches. This compression of the attack cycle forces enterprises to rethink their security assumptions and verification processes for financial transactions.

Disruption and impact

Microsoft's operation, conducted with industry partners including SpyCloud, seized 50 websites and 150 domains used to operate the platform. The UK Metropolitan Police Service arrested two suspects in connection with the operation.

Victim organizations spanned multiple sectors including wholesale distribution, construction, financial services, real estate, higher education, and healthcare. The United States saw the highest concentration of compromised accounts, followed by Canada, the UK, Australia, India, and France.

Microsoft emphasized that organizations must now assume compromised inboxes can be fully analyzed within minutes. The company recommends implementing strong identity protections and independently verifying any requests to change payment information or redirect funds through trusted secondary channels.

Details of the disruption operation were first reported by Dan Goodin at Ars Technica.

#business email compromise#ai security#oauth exploitation#microsoft security#cybercrime platforms#fraud automation

This is an original analysis by the Omega editorial team. Source reporting: AI Watch.

Want systems like this working for your business?

Book a Call

More in Security

Security· 3 min read

Bifrost AI Gateway Flaw Enables Remote Code Execution

Unauthenticated attackers can run arbitrary commands and steal API keys through a critical vulnerability in the open-source LLM routing platform.

Via AI Watch · Sep 22, 2026
Security· 3 min read

AI Deployment Accelerates Amid Rising Public Anxiety and Regulatory Pushback

From military near-misses to data center battles, artificial intelligence is reshaping communities faster than governments can respond.

Via AI Watch · Sep 22, 2026
Security· 3 min read

Microsoft Disrupts EvilTokens AI Chatbot Built for Email Fraud

The cybercrime platform used AI to analyze stolen inboxes, identify targets, and automate business email compromise attacks at scale.

Via AI Watch · Sep 22, 2026