Microsoft Dismantles EvilTokens Cybercrime Platform That Used AI Chatbots to Breach 12,000 Accounts Globally; Details Here

Microsoft has dismantled EvilTokens, a subscription-based cybercrime platform that used an AI chatbot to target more than 12,000 accounts across over 10,000 organisations. The service automated phishing campaigns and exploited device code authentication to bypass security controls. Authorities seized 50 websites, disabled over 150 domains and arrested two suspects in the UK.

Representational Image (Photo Credits: Pexels)

Microsoft announced the successful dismantling of a sophisticated subscription-based cybercrime platform known as EvilTokens, which utilized an artificial intelligence chatbot to breach more than 12,000 accounts across over 10,000 organisations worldwide. The operation relied on automated tools to target multiple sectors, including financial services, healthcare, and higher education, spanning several countries such as the United States, Canada, the United Kingdom, Australia, India, and France.

As per a post by Microsoft, EvilTokens helped cybercriminals access email accounts. the malicious service first appeared on a Telegram channel in February, charging users an initial fee of USD 1500 followed by a recurring monthly charge of USD 500. The platform offered a comprehensive service that streamlined the process of compromising email accounts at scale, allowing operators to automate mass phishing campaigns and exploit legitimate authentication protocols to bypass traditional security defenses. Bluevine Layoffs: 80 Indian Employees ‘Fired in 5-Minute Google Meet Call’.

How EvilTokens Used Artificial Intelligence

At the core of the operation was an artificial intelligence chatbot designed to assist cybercriminals in navigating compromised inboxes and maximizing financial gain. Once inside an account, the chatbot analyzed victim communications to identify high-value targets, determine payment approval hierarchies, and recognize trusted relationships. Furthermore, the system recommended specific fraud strategies and drafted convincing follow-up emails impersonating trusted contacts, manipulating recipients into transferring funds to attacker-controlled accounts.

Exploiting Legitimate Device Code Authentication

The infrastructure leveraged a legitimate OAuth authentication process known as device code authentication, which was originally intended for hardware lacking standard login interfaces like smart TVs. Victims received spam emails containing malicious links that redirected them to pages running hidden automation scripts. These scripts interacted with the Microsoft identity provider in real time to generate device codes, prompting victims to authorize unauthorized devices through official login portals and enabling attackers to bypass conventional signature-based detection systems. OpenAI Rogue AI Agents Compromised Hugging Face Accounts and Probed Infrastructure Months Before Breach Disclosure: Report.

Law enforcement agencies and technology partners responded by seizing 50 websites and disabling more than 150 additional domains tied to the supporting infrastructure. In the United Kingdom, the Metropolitan Police Service cybercrime team arrested two men on suspicion of offenses connected to the operation. Microsoft highlighted that this incident signifies a major evolution in how mass account compromises and subsequent financial frauds are executed in the modern threat landscape.

Rating:5

TruLY Score 5 – Trustworthy | On a Trust Scale of 0-5 this article has scored 5 on LatestLY. It is verified through official sources (Microsoft ). The information is thoroughly cross-checked and confirmed. You can confidently share this article with your friends and family, knowing it is trustworthy and reliable.

(The above story first appeared on LatestLY on Sep 23, 2026 10:10 PM IST. For more news and updates on politics, world, sports, entertainment and lifestyle, log on to our website latestly.com).

Share Now

Share Now