Microsoft dismantles AI-powered scam platform that hacked 12,000 accounts
Microsoft and industry partners have disrupted EvilTokens, a subscription-based scam platform whose AI chatbot helped criminals compromise 12,000 Microsoft accounts worldwide. Two men were arrested in the UK on suspicion of involvement.

Microsoft announced Tuesday that it led an industry-wide operation to shut down a subscription-based criminal platform called EvilTokens, which over the course of a few months helped attackers compromise 12,000 Microsoft accounts belonging to roughly 10,000 organizations globally.
The platform was advertised through a Telegram channel starting in February, charging users an initial $1,500 fee followed by a recurring $500 monthly charge. EvilTokens bundled together the multiple steps needed to hack email accounts at scale into a single service.
AI helped pick the most profitable targets
Once access was gained, the platform offered tools to analyze victims' inboxes, letting criminals identify the most lucrative targets and draft convincing follow-up emails designed to trick company employees into transferring money to attacker-controlled accounts. According to Microsoft, an AI-style chatbot sat at the core of the service, capable of analyzing a victim's inbox to spot trusted relationships, payment authorizations, and other conditions where fraud was likely to succeed. The chatbot could even suggest fraud tactics, including drafting messages impersonating trusted contacts.
The largest concentration of affected accounts was in the United States, followed by Canada, the UK, Australia, India, and France. Victim organizations spanned wholesale distribution, construction, financial services, real estate, higher education, and healthcare.
Seizures and arrests followed
Using legal processes and a network of partners, Microsoft seized 50 websites and an additional 150 domains that had been used to run EvilTokens. London's Metropolitan Police arrested two men on suspicion of offenses linked to the criminal platform.
The account compromises relied on a legitimate OAuth authentication method known as device code authentication, originally designed for TVs and other devices that lack a standard login interface. In this process, a device displays a code that the user enters into a browser on a separate device, which is then authenticated.


