Microsoft Dismantles 'EvilTokens' AI-Powered Fraud Platform Linked to 12,000 Hacked Inboxes
Microsoft, working with a group of industry partners, has disrupted EvilTokens, a cybercrime platform that investigators linked to more than 12,000 compromised Microsoft email inboxes across over 10,000 organisations globally. Acting on a federal court order issued on 15 September, Microsoft and its partners seized 50 websites used by the phishing-as-a-service operation and disabled more than 175 supporting domains.
Launched in February 2026, EvilTokens used an AI-style chatbot to help criminals analyse stolen inbox data, identify trusted business relationships, and pinpoint payment authorisations that could be exploited for fraud. Rather than just writing convincing phishing messages, the AI reportedly helped attackers decide who to impersonate and how to extract the most money from a compromised relationship. The platform stole session tokens, letting criminals sift through victims' inboxes and maintain ongoing access, a technique commonly used in business email compromise scams.
About 1,000 cybercriminals used the service during its operation. Microsoft says it cannot estimate total losses caused by EvilTokens, but has linked at least 13 FBI Internet Crime Complaint Center reports to the platform, representing around $1.7 million in reported losses, a figure it believes is conservative given underreporting.