Security News

Microsoft Dismantles 'EvilTokens' AI-Powered Fraud Platform Linked to 12,000 Hacked Inboxes

CyberScoop · 23 Sept 2026
Key Takeaway Small businesses should enable multi-factor authentication and monitor for suspicious inbox rules or session activity, as stolen login tokens can let attackers bypass passwords entirely.

Microsoft, working with a group of industry partners, has disrupted EvilTokens, a cybercrime platform that investigators linked to more than 12,000 compromised Microsoft email inboxes across over 10,000 organisations globally. Acting on a federal court order issued on 15 September, Microsoft and its partners seized 50 websites used by the phishing-as-a-service operation and disabled more than 175 supporting domains.

Launched in February 2026, EvilTokens used an AI-style chatbot to help criminals analyse stolen inbox data, identify trusted business relationships, and pinpoint payment authorisations that could be exploited for fraud. Rather than just writing convincing phishing messages, the AI reportedly helped attackers decide who to impersonate and how to extract the most money from a compromised relationship. The platform stole session tokens, letting criminals sift through victims' inboxes and maintain ongoing access, a technique commonly used in business email compromise scams.

About 1,000 cybercriminals used the service during its operation. Microsoft says it cannot estimate total losses caused by EvilTokens, but has linked at least 13 FBI Internet Crime Complaint Center reports to the platform, representing around $1.7 million in reported losses, a figure it believes is conservative given underreporting.

phishing business email compromise Microsoft AI threats cybercrime takedown

Summarised by CISO AI from CyberScoop. We link back to every original so you can read it yourself.