Microsoft Takes Down EvilTokens After AI-Powered Attacks Hit 10,000 Organizations


EvilTokens microsoft
Image credit: EvilTokens

Microsoft has disrupted EvilTokens, an AI-powered cybercrime platform linked to more than 12,000 compromised email inboxes across over 10,000 organizations worldwide.

The service launched in February 2026 and used AI to help attackers analyze stolen inboxes, identify financial conversations, and prepare convincing fraud attempts.

Microsoft seized 50 websites linked to EvilTokens

Microsoft and its partners seized 50 websites and disabled more than 150 additional domains connected to the platform.

Once attackers gained access to an email account, EvilTokens could analyze messages and identify trusted contacts, payment responsibilities, and ongoing financial conversations.

The platform could then recommend fraud strategies and generate messages that impersonated legitimate contacts.

According to Microsoft, the AI helped criminals determine who to target, who to impersonate, and which conversations offered the best opportunity for financial fraud.

EvilTokens used device-code phishing

EvilTokens used device-code phishing to gain access to Microsoft accounts without directly collecting users’ passwords.

This type of access could remain active even after a password reset if administrators did not also revoke the associated sessions and authentication tokens.

The previously reported ARToken phishing platform was also associated with EvilTokens and exposed techniques for stealing Microsoft 365 authentication tokens.

Microsoft worked with security and technology companies

Microsoft and Health-ISAC worked with Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, Shadowserver, and TRM Labs on the disruption.

Microsoft described the operation as its first action against an end-to-end AI-enabled cybercrime service.

The company also warned that AI can now help attackers understand a compromised inbox and identify fraud opportunities within minutes.

Organizations should independently verify payment changes, fund transfers, and unusual transaction requests through a trusted second communication channel.

EvilTokens is not the only recent example of AI appearing in cyberattacks. ClosedQuorum malware used four AI models to help coordinate attack decisions, while the TrustSink attack demonstrated how attackers could steal passwords during Microsoft Entra MFA sign-ins.

More about the topics: microsoft, security

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages