Microsoft led an industry-wide takedown of EvilTokens, a subscription platform whose AI chatbot helped criminals compromise 12,000 Microsoft accounts.
A scam platform with an AI concierge
Microsoft said Tuesday that it led an industry-wide effort to disrupt EvilTokens, a subscription service built to industrialize the theft of email accounts. According to the company, the platform was used to compromise 12,000 Microsoft accounts over a span of just a few months. This wasn't a scrappy phishing kit pulled off a forum — it was a packaged, recurring-revenue business with a chatbot at the core.
The numbers make the business model plain. EvilTokens debuted over a Telegram channel in February, charging an initial $1,500 fee and a recurring $500 charge every month after that. In exchange, subscribers got a single service that streamlined most of the steps required to compromise email accounts in large numbers.
What customers were paying for
EvilTokens wasn't just a credential-harvesting tool. Once access was obtained, the platform walked its users through the operational work that ordinarily separates a script kiddie from a profitable fraud operation:
- Inbox analysis — parsing a victim's mail to understand who they are and what they control.
- Target selection — identifying which contacts and relationships offered the biggest potential payouts.
- Follow-up drafting — generating realistic ruses designed to trick company employees into transferring funds to attacker-controlled accounts.
At the center: an AI-style chatbot
The distinguishing feature of EvilTokens was not the intrusion itself, but the layer sitting on top of it. Microsoft described the chatbot as the heart of the operation:
“While EvilTokens helped cybercriminals access email accounts, at the center of the service was an AI-style chatbot that could analyze a victim's inbox and help criminals identify trusted relationships, payment authorizations, and sensitive responsibilities, as well as other circumstances where fraud was most likely to succeed.”
“The platform could even recommend fraud strategies, including drafting messages that impersonated trusted contacts to help criminals trick victims into taking action.”
That description is worth pausing on. The chatbot wasn't a generic assistant bolted onto a phishing panel — it was a targeting engine. It mapped organizational trust: who approves payments, who holds sensitive responsibilities, which relationships a spoofed message could plausibly exploit. In other words, it automated the reconnaissance and social-engineering judgment that used to require a skilled human operator.
Minutes, not days
The disrupt-the-platform framing matters because of what the service compressed. Business email compromise has traditionally been a labor-intensive crime: gain access, read enough mail to learn the org chart, identify an invoice or a wire transfer in flight, then craft a message that survives scrutiny. EvilTokens turned each of those stages into a recommendation the subscriber could act on.
That shift — from skilled operator to assisted tooling — is the broader story here. When the expensive, human part of an attack is packaged as a monthly subscription, the population of people capable of running it expands dramatically, and the cost of attempted fraud falls. Twelve thousand compromised accounts in a few months is the visible output of that math.
Why the disruption is only half the story
Microsoft said the takedown was industry-wide, a phrasing that signals coordination across multiple parties rather than a single company acting alone. Disrupting the infrastructure, however, does not undo the access that was already sold, nor the inboxes that were already compromised.
For defenders, the practical takeaways are familiar but newly urgent:
- Treat account takeover as a fraud problem, not just an access problem. The stolen mailbox is the means; the payment is the objective.
- Assume reconnaissance is automated. Trust relationships and payment authorization chains inside your organization are themselves attack surface.
- Verify out-of-band. Any request to move funds that originates in email — even from a known, trusted contact — deserves a second channel and a human check.
EvilTokens is gone, at least for now. The model it validated — criminal tooling sold as an AI-assisted subscription — is not.