Microsoft announced on 22 September that it had disrupted EvilTokens, a subscription cybercrime service whose AI chatbot searched compromised email accounts for opportunities to commit fraud. The company linked the service to more than 12,000 compromised inboxes at over 10,000 organisations worldwide within months of its February 2026 launch, according to an account of the operation by Steven Masada, an executive in Microsoft’s Digital Crimes Unit.
Key points
- Microsoft linked EvilTokens to more than 12,000 compromised inboxes across over 10,000 organisations.
- Microsoft and its partners seized 50 websites and disabled more than 150 supporting domains.
- The service used stolen account access and an AI chatbot to identify financial conversations and possible targets for impersonation.
- Metropolitan Police officers arrested two men on 11 September in connection with the alleged operation of EvilTokens.
EvilTokens turned mailbox access into fraud preparation
Getting into an account was the first part of the service. Microsoft said EvilTokens induced people to enter an authentication code on Microsoft’s genuine sign-in page, completing a sign-in process that gave criminals access without exposing the account password. The Hacker News reported that Huntress had documented the platform in March as a service abusing the OAuth 2.0 device authorisation flow. In that flow, a code meant to approve access for one device can instead be entered by the account holder to approve access sought by an attacker.
That distinction matters when an account is being secured. Microsoft said the access granted through the code could persist after a password reset if the associated sessions and tokens were left active. A token is the continuing proof of an approved sign-in: changing the password need not cancel a session that already holds one. The company said affected accounts therefore required attention to those sessions and tokens as well as to the password.
Once EvilTokens had access, Microsoft said its chatbot could condense and translate messages, find conversations about payments, map roles within an organisation and identify relationships that an impersonator might exploit. Its prepared prompts sought wire-transfer discussions and vendor invoices, while the service could recommend whom to impersonate and draft messages posing as trusted contacts. The AI’s role was therefore tied to material taken from an actual inbox, rather than only to composing a generic phishing message.
Checking an invoice could become harder if earlier messages and payment discussions were available to someone preparing a fraudulent request. A request to send money could draw on details from a real exchange, while the familiar-looking correspondence behind it could belong to a compromised account.
Microsoft said EvilTokens was sold through Telegram for a $1,500 initiation fee and a recurring $500 subscription. That package joined account access, mailbox analysis, target selection and preparation for financial fraud in one service. Microsoft’s investigators also found evidence that AI had assisted in building large parts of the platform and that it used capabilities from multiple AI models. Those are the company’s findings about this operation, separate from its count of inboxes it linked to the service.
Court order reached 50 EvilTokens websites
With authorisation from the US District Court for the Eastern District of Virginia, Microsoft and its partners seized 50 websites used to operate EvilTokens and disabled more than 150 other domains supporting it, Microsoft said. The distinction is material: the websites served the operation itself, while the additional domains were part of the infrastructure around it. Disabling both cut into the service through which customers obtained its tools and the online addresses that supported them.
Health-ISAC joined Microsoft’s legal action as a co-plaintiff because healthcare organisations were among those targeted, according to Microsoft. Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, the Shadowserver Foundation and TRM Labs also worked on the disruption. The company said the service relied on hosting, cloud, AI and financial services that criminals had repurposed, making the operation one that crossed several providers rather than a single site.
Microsoft observed the highest concentrations of victim activity in the United States, Canada, the United Kingdom, Australia, India and France. It identified affected organisations in sectors including financial services, healthcare, higher education, real estate and construction. The company said it notified affected customers, helped them address compromised accounts and shared intelligence for defensive and investigative work.
Two men arrested on 11 September
The disruption also involved police action in Britain. Metropolitan Police cybercrime officers arrested two men, aged 32 and 38, on 11 September on suspicion of offences connected with the alleged operation of EvilTokens, CircleID reported. The arrests concerned the alleged operation of the service, rather than each compromise Microsoft counted across the affected organisations.
The two men were subsequently released on conditional police bail while the investigation continued, CircleID reported.