Microsoft disrupts AI-powered cybercrime platform linked to 12,000 compromised accounts

← Back to the feed

Microsoft disrupts AI-powered cybercrime platform linked to 12,000 compromised accounts

Ars Technica · 3 hours ago

Microsoft has disrupted an AI-powered cybercriminal platform named EvilTokens that compromised 12,000 accounts across 10,000 organisations worldwide. The subscription-based service, which charged $1,500 initially and $500 monthly, provided criminals with an end-to-end platform to orchestrate mass email account compromises and fraud at scale. This disruption matters because it demonstrates how sophisticated criminal tools have become, combining artificial intelligence with automated attack systems to streamline what would traditionally require significant manual effort.

EvilTokens, introduced on Telegram in February, exploited device code authentication—a legitimate OAuth process designed for input-constrained devices—to gain unauthorised access to Microsoft Entra accounts. The platform analysed victim inboxes using AI to identify employees with financial authority, their managers, and convincing fraud scenarios, then automatically generated impersonation messages to trick victims into transferring funds to attacker-controlled accounts. The US had the highest concentration of affected organisations, with Canada, the UK, Australia, India, and France also significantly impacted across sectors including financial services, healthcare, construction, and higher education. Microsoft seized 50 websites and 150 domains in the operation, whilst the UK's Metropolitan Police arrested two men in connection with the platform.

  • AI-powered platform automated mass email compromises affecting 12,000 accounts globally
  • Exploited legitimate OAuth device authentication to bypass security measures
  • Microsoft and partners seized infrastructure; UK police arrested two suspects

Software

Read the full article at the source →

Originally published by Ars Technica as “Microsoft disrupts AI-assisted platform that compromised 12,000 accounts”.