Microsoft disrupts AI-assisted platform that compromised 12,000 accounts
Sep 22, 2026, 12:45 PM · Ars Technica

EvilTokens turned inbox compromise into a subscription product — AI for target picking and lure drafting — until Microsoft and partners tore down the shop.
Why it matters
Microsoft said it led an industry disruption of EvilTokens, a subscription scam platform that used an AI-style chatbot to help compromise about 12,000 Microsoft accounts across roughly 10,000 organizations in a few months.
The platform charged $1,500 up front and $500 a month. It didn’t invent phishing; it industrialized the post-compromise step — reading inboxes at scale and drafting believable fraud.
From the desk
We’re not surprised AI shows up in crimeware. We’re noting how fast the economics flipped.
EvilTokens launched over Telegram in February. After accounts were taken via abused OAuth device-code authentication — spam lures, hidden scripts talking to Microsoft Entra, victims pasting codes into the real device-login portal — the AI layer did the high-value work. Microsoft says the chatbot could analyze a victim’s inbox, map trusted relationships and payment authority, recommend fraud strategies, and draft messages impersonating trusted contacts. The platform analyzed 5,000 compromised emails at a time. Victims spanned wholesale distribution, construction, financial services, real estate, higher education, and healthcare, concentrated in the US, then Canada, the UK, Australia, India, and France.
Microsoft and partners seized 50 websites and 150 more domains. UK Metropolitan Police arrested two men on suspicion of related offenses. SpyCloud assisted.
Microsoft’s own lesson line is the one we’re carrying: once an inbox is compromised, criminals may understand its contents in minutes, not days. That’s the shift. Manual charting of org hierarchies used to buy defenders time. AI collapses that delay.
Useful AI didn’t build EvilTokens — but the same inbox-analysis skills that help a helpdesk triage mail also help a fraud desk pick the CFO’s assistant. Defenders need the same speed: anomaly detection on device-code flows, second-channel payment verification, and assuming post-compromise comprehension is near-instant.
I’m watching copycats. Subscription crimeware with an AI middle layer will reappear under new brands. The disruption matters; the product category now exists.
Context
Ars Technica by Dan Goodin, Sep 22, 2026, reporting Microsoft’s disruption of the EvilTokens platform and the OAuth device-code authentication abuse path used for initial access.
Who feels it
- Enterprises
- Treat compromised mailboxes as fully mapped within minutes; verify payment changes on a trusted second channel.
- Identity / SOC teams
- Monitor and constrain device-code OAuth flows; signature-based filters missed EvilTokens’ dynamic Node.js backend.
- Sectors hit hardest
- Wholesale, construction, finance, real estate, higher ed, and healthcare should assume they were in-scope for this tooling class.
- AI product builders
- Inbox-analysis agents need abuse monitoring — the same capability is now proven crimeware.
What to watch
- Whether Microsoft publishes lasting Entra controls or defaults that harden device-code auth.
- Copycat Telegram offerings replacing EvilTokens’ feature set.
- SpyCloud or Microsoft follow-on victim guidance and takedown tallies.
- Arrest outcomes from the UK Metropolitan Police Service case.
Companies: Microsoft