Microsoft disrupts EvilTokens, an AI-enabled cybercrime service linked to 12,000 compromised inboxes | #cybercrime | #infosec


Microsoft disrupts EvilTokens, an AI‑enabled subscription platform linked to more than 12,000 compromised email inboxes.

Microsoft announced on 22 September 2026 that its Digital Crimes Unit (DCU), working with industry partners and law-enforcement authorities, had disrupted EvilTokens, a subscription-based cybercrime service that used artificial intelligence across multiple stages of the attack chain. According to Microsoft, the platform had been linked to more than 12.000 compromised email inboxes belonging to users across more than 10.000 organisations worldwide within months of its launch in February 2026. Victim organisations included entities in financial services, healthcare, higher education, construction, real estate and wholesale distribution.

EvilTokens combined phishing, account compromise, mailbox reconnaissance and fraud preparation in a single commercial service. The platform abused the legitimate device-code authentication process to obtain authentication tokens without requiring victims to disclose their passwords. Once access had been obtained, its AI-enabled tools could analyse mailbox contents, identify organisational relationships and locate information associated with invoices, payment authorisations and financial transactions. The system could then help users identify high-value targets and generate messages designed to impersonate trusted individuals or exploit existing business relationships.

This represents an important evolution in the cybercrime-as-a-service model. Criminals have long been able to purchase phishing kits, stolen credentials and infrastructure, but EvilTokens integrated these capabilities with AI-based analysis of compromised environments. Microsoft reported that the platform could process large volumes of email and identify employees with financial authority, their relationships with managers and suppliers, and circumstances in which fraudulent payment requests might appear credible. AI therefore served not simply as a tool for generating phishing text, but as an analytical layer connecting initial access with reconnaissance, target selection and financial exploitation.

The commercial structure further lowered the barrier to entry. EvilTokens was reportedly marketed through Telegram with an initial fee of US$1.500 and a recurring subscription of US$500. The service provided customers with a ready-made operational infrastructure rather than requiring them to develop their own phishing and post-compromise capabilities. Microsoft investigators also found evidence that AI had been used in the development of parts of the platform itself, illustrating a two-sided effect in which AI can reduce the resources required both to build cybercrime tools and to operate them.

The disruption was carried out through a combination of legal, technical and law-enforcement measures. Microsoft and its partners obtained court authorisation in the United States and seized 50 websites associated with the service, while more than 150 additional domains connected to its supporting infrastructure were disabled. Microsoft also notified affected customers and supported remediation. In the United Kingdom, the Metropolitan Police Service arrested two men suspected of involvement in the operation; both were subsequently released on police bail while investigations continue.

The immediate outcome is the disruption of a cybercrime platform that had enabled large-scale compromise and fraud, together with the identification and notification of affected organisations. More strategically, however, the operation demonstrates the value of combining private-sector threat intelligence, infrastructure disruption, judicial mechanisms and international law enforcement. It also provides evidence that AI can compress the period between obtaining access to an account and exploiting the information contained within it: activities that previously required substantial manual reconnaissance can increasingly be automated and performed at scale.

At the same time, disrupting one platform does not eliminate the underlying model. The tools and techniques demonstrated by EvilTokens can potentially be reproduced by other cybercrime providers, meaning that the principal long-term outcome may be a shift in defensive priorities towards identity security, token protection, detection of abnormal mailbox activity and rapid response to compromised accounts.

Why does it matter?

The important development is that AI has been integrated into the full cybercrime workflow, reducing the expertise and time required to move from account compromise to financial exploitation. The case the growing convergence between AI-enabled cybercrime and business email compromise. The central security problem is no longer necessarily the sophistication of the initial phishing message, but what attackers can do after gaining legitimate access to an account. Once an inbox becomes a source of organisational intelligence, AI can help identify decision-makers, trusted relationships and financial processes, turning previously passive access into an operational capability for fraud. This places greater importance on identity-centred security and on monitoring activity after authentication rather than treating successful login as evidence of trust.

EvilTokens successful takedown is significant as an early example of how generative and analytical AI may transform the economics and organisation of cybercrime. The development points to a broader trend from cybercrime tools that automate individual tasks towards integrated services that can connect initial compromise, reconnaissance, social engineering and monetisation. This potentially lowers the expertise required to conduct sophisticated attacks while increasing their scalability and speed.

Equally important is the defensive dimension: the takedown demonstrates an emerging model of cybercrime governance in which technology companies, law enforcement, infrastructure providers and specialised security firms combine technical intelligence with legal and operational measures. EvilTokens therefore illustrates both sides of an evolving AI–cybersecurity relationship: AI can increase the scale and efficiency of criminal exploitation, while also becoming an important tool for investigation and disruption.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!



Click Here For The Original Source.

——————————————————–

..........

.

.