Microsoft takedown of AI-driven scam service that hit 12,000 accounts
Microsoft announced on September 22, 2026 that it helped dismantle the subscription-based AI-driven fraud platform EvilTokens, which had compromised roughly 12,000 Microsoft accounts across about 10,000 organizations worldwide after appearing on Telegram in February 2026.
GGLOBAIINDUSTRY DESKSHARE
Microsoft announced on September 22, 2026 that it helped dismantle the subscription-based AI-driven fraud platform EvilTokens, whi…
Share this post
Short answer: Microsoft announced on September 22, 2026 that it helped dismantle the subscription-based AI-driven fraud platform EvilTokens, which had compromised roughly 12,000 Microsoft accounts across about 10,000 organizations worldwide after appearing on Telegram in February 2026.
Microsoft takedown of EvilTokens AI scam service
Paragraph1: Microsoft announced on September 22, 2026 that it helped dismantle a subscription-based fraud platform called EvilTokens, which had been used to break into roughly twelve thousand Microsoft accounts belonging to about ten thousand organizations worldwide. The service first appeared on a Telegram channel in February of the same year and charged an upfront fee of fifteen hundred dollars followed by a monthly payment of five hundred dollars.
How EvilTokens bundled credential theft steps
Paragraph2: EvilTokens bundled several steps of a credential-theft operation into a single offering. Its core feature was an AI-powered chatbot that could scan a compromised mailbox, spot trusted contacts, pinpoint employees with authority to move money, and suggest convincing pretexts for fraud. The chatbot also drafted messages that mimicked legitimate senders, increasing the odds that victims would follow attacker instructions.
Paragraph3: The attackers abused the OAuth device-code flow, a method intended for devices without keyboards, such as smart TVs. Victims were lured to a page that ran a hidden script, which interacted with Microsoft Entra in real time to generate a device code. The code was then presented to the user with instructions to enter it on the official Microsoft login portal, granting the attacker a session token. Because the backend used custom Node.js logic, the activity evaded typical signature-based defenses.
How EvilTokens let criminals move from inbox to fund transfer in minutes
Paragraph4: Microsoft said the platform allowed criminals to move from inbox access to fraudulent fund transfers in minutes rather than days. By automating the analysis of thousands of emails at once, EvilTokens quickly built maps of organizational hierarchies, identified suppliers and customers, and highlighted the most lucrative targets. Victims spanned industries including wholesale distribution, construction, finance, real estate, higher education, and healthcare, with the greatest concentration in the United States, followed by Canada, the United Kingdom, Australia, India, and France.
Microsoft seizes websites domains in EvilTokens takedown
Paragraph5: To disrupt the operation, Microsoft coordinated with industry partners and used legal processes to seize fifty websites and one hundred fifty domains linked to EvilTokens. The United Kingdom’s Metropolitan Police Service arrested two individuals suspected of involvement in the scheme. SpyCloud, a security firm that assisted in the takedown, published additional details about the affected organizations.
How organizations should respond to mailbox breach after EvilTokens
Paragraph6: Microsoft advises that organizations treat any mailbox breach as an immediate risk: attackers can glean useful information almost instantly. Strong identity protections and continuous monitoring remain essential, but companies should also verify any request to change payment details, redirect funds, or approve unusual transactions through a separate, trusted channel before acting. This extra verification step can stop fraud even if an account has already been compromised.
We must keep same length (word count similar). Hard to exactly match, but we can approximate. We'll try to keep similar word counts per paragraph.
Paragraph1: "Microsoft announced on September 22, 2026 that it helped dismantle a subscription-based fraud platform called EvilTokens, which had been used to break into roughly twelve thousand Microsoft accounts belonging to about ten thousand organizations worldwide. The service first appeared on a Telegram channel in February of the same year and charged an upfront fee of fifteen hundred dollars followed by a monthly payment of five hundred dollars."
Paragraph2: "EvilTokens bundled several steps of a credential-theft operation into a single offering. Its core feature was an AI-powered chatbot that could scan a compromised mailbox, spot trusted contacts, pinpoint employees with authority to move money, and suggest convincing pretexts for fraud. The chatbot also drafted messages that mimicked legitimate senders, increasing the odds that victims would follow attacker instructions."
Paragraph3: "The attackers abused the OAuth device-code flow, a method intended for devices without keyboards, such as smart TVs. Victims were lured to a page that ran a hidden script, which interacted with Microsoft Entra in real time to generate a device code. The code was then presented to the user with instructions to enter it on the official Microsoft login portal, granting the attacker a session token. Because the backend used custom Node.js logic, the activity evaded typical signature-based defenses."
Paragraph4: "Microsoft said the platform allowed criminals to move from inbox access to fraudulent fund transfers in minutes rather than days. By automating the analysis of thousands of emails at once, EvilTokens quickly built maps of organizational hierarchies, identified suppliers and customers, and highlighted the most lucrative targets. Victims spanned industries including wholesale distribution, construction, finance, real estate, higher education, and healthcare, with the greatest concentration in the United States, followed by Canada, the United Kingdom, Australia, India, and France."
Paragraph5: "To disrupt the operation, Microsoft coordinated with industry partners and used legal processes to seize fifty websites and one hundred fifty domains linked to EvilTokens. The United Kingdom’s Metropolitan Police Service arrested two individuals suspected of involvement in the scheme. SpyCloud, a security firm that assisted in the takedown, published additional details about the affected organizations."
What is EvilTokens and what were its subscription fees?
EvilTokens was a subscription-based fraud platform that gave attackers access to roughly twelve thousand Microsoft accounts across about ten thousand organizations worldwide. It charged an upfront fee of $1,500 and then a monthly payment of $500, first appearing on a Telegram channel in February 2026.
How did EvilTokens use an AI-powered chatbot to aid fraud?
The platform’s core feature was an AI-powered chatbot that could scan a compromised mailbox, identify trusted contacts, pinpoint employees authorized to move money, and suggest convincing pretexts. It also drafted messages that mimicked legitimate senders, making victims more likely to follow attacker instructions.
Which authentication flow did attackers abuse and how did it work?
Attackers abused the OAuth device-code flow, intended for devices without keyboards. They lured victims to a page running a hidden script that interacted with Microsoft Entra in real time to generate a device code. Users were told to enter that code on the official Microsoft login portal, granting the attacker a session token.
What steps did Microsoft take to disrupt EvilTokens and who assisted?
Microsoft coordinated with industry partners and used legal processes to seize fifty websites and one hundred fifty domains linked to EvilTokens. The UK’s Metropolitan Police Service arrested two suspects, and security firm SpyCloud helped with the takedown and published additional details about the affected organizations.
UK AI Security Institute and the EvalEval Coalition have published reproducible benchmark results, releasing Evaluation Cards for five core benchmarks-HealthBench, FrontierMath, Humanity's Last Exam, SWE-Bench Pro and Terminal-Bench 2.0-tested on six frontier LLMs and two cyber-focused evaluations, using the Every Eval Ever schema to ensure transparency.
Anthropic’s Opus 5.5 and OpenAI’s GPT-6 Sol and Luna models lower token prices-Opus 5.5 at $4 input and $20 output per million tokens (20 % cheaper than Opus 5) and Sol/Luna at $2/$10 and $0.10/$0.50 per million tokens, roughly half the cost of their predecessors-offering developers reduced AI expenses.
Rabbit has launched a cloud-based AI agent called OS3 that runs on any Windows, macOS, or Linux PC without dedicated hardware, letting users connect up to five devices, choose their own AI models, and access the agent via desktop, Telegram, iMessage, or the legacy R1.
NO COMMENTS YET
Comments are open. Have a thought or a question? Share it below.