AI Platform Behind 12,000 E-mail Breaches Shut Down

Microsoft has disrupted EvilTokens, a cybercrime service that used AI to help attackers break into e-mail accounts, study their victims, and build convincing financial scams.

The platform moved quickly. Since launching in February, EvilTokens had been tied to more than 12,000 compromised inboxes across over 10,000 organizations worldwide, according to Microsoft. Its victims included businesses and institutions in financial services, healthcare, construction, real estate, wholesale distribution, and higher education.

Microsoft and its partners seized 50 websites used to operate EvilTokens and disabled more than 150 additional domains supporting the service. The Metropolitan Police Service in the United Kingdom also arrested two men on Sept. 11 in connection with the alleged operation.

At the center of EvilTokens was an AI chatbot designed specifically for cybercrime. Once attackers gained access to an inbox, the chatbot could analyze messages, map relationships, identify employees involved in payments, and recommend ways to impersonate trusted contacts.

Microsoft said the platform helped criminals determine "who to target, who to impersonate," and how to get the most money from a compromised organization.

Business e-mail compromise has traditionally required attackers to manually comb through messages, learn how an organization handles payments, and find the right person to impersonate. However, EvilTokens simplified the entire process by automating much of that work.

The tools could quickly sort through a stolen inbox, summarize or translate messages, find invoices and wire-transfer discussions, and identify the people who moved money. EvilTokens could then draft messages that sounded like they came from the victim. It packaged all of this with mailbox access, phishing tools, management dashboards, and even customer support.

The service was sold through Telegram for a $1,500 startup fee, followed by a $500 monthly subscription. Microsoft's complaint also described a bulk e-mail tool that cost $600 a month and a more advanced e-mail delivery platform priced at $1,000 a month.

To break into a target, EvilTokens relied on device-code phishing. Victims were sent to a real Microsoft sign-in page and persuaded to enter an authentication code. The login process looked legitimate because it was, but the code quietly authorized a session controlled by the attacker.

That also made cleanup more complicated. The attackers stole OAuth tokens and authenticated sessions instead of passwords, so a password reset alone might not remove their access. Administrators also needed to revoke the stolen tokens and active sessions.

According to Microsoft's complaint,  EvilTokens used fake Microsoft 365 security notices and other branded templates to direct users into the device authentication flow. Once inside, attackers could use Microsoft Graph and other APIs to search and monitor a mailbox.

The company also found that AI played a role in creating EvilTokens itself. Investigators said much of the platform appeared to have been "vibe coded," with its developers using AI to quickly build and expand the service. EvilTokens reportedly drew on multiple AI models, including improperly integrated services from Groq and OpenAI.

Microsoft and Health-ISAC filed a civil lawsuit in the U.S. District Court for the Eastern District of Virginia against Felix Utomi, Waidi Segun Adams, and five unnamed defendants. The complaint alleges violations of the Computer Fraud and Abuse Act, Electronic Communications Privacy Act, Lanham Act and federal racketeering law.

The court authorized Microsoft to take control of or disable domains connected to the operation. Microsoft worked with Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, the Shadowserver Foundation, and TRM Labs on the disruption. Health-ISAC joined the case because healthcare organizations were among the targets.

This marks the Microsoft Digital Crimes Unit's 40th court-authorized disruption and its first targeting an end-to-end, AI-enabled cybercrime service.

EvilTokens' infrastructure may be offline, but the model behind it is unlikely to disappear. The operation showed how AI can turn a stolen inbox into an immediately useful fraud playbook, allowing less-experienced criminals to launch attacks that once required considerable time and skill.

For more information, read the Microsoft blog post.

About the Author

Chris Paoli (@ChrisPaoli5) is the associate editor for Converge360.

Featured

  • Hootsuite

    Beyond the Feed: How Higher Ed Turns Social Media Into a Measurable Enrollment Engine

    More than half of prospective students research programs on social media before visiting a university website, and nearly half will skip applying to a school that looks inactive online. Hootsuite, the all-in-one social OS platform trusted by more than 2,000 higher education institutions, helps campus teams turn everyday posts into measurable outcomes, from applications to alumni giving.

  • A glowing digital brain with neural connections and light trails

    AI Giants Warn It May Be Time to Slow Down

    For years, leaders in the artificial intelligence industry have warned that increasingly capable AI systems could eventually become dangerous, all the while continuing to race to build them. Now, their sentiments have changed.

  • lock icons, shields, and glowing data paths

    Research Studies Suggest AI Is Accelerating Familiar Cyber Attacks

    Research released around the recent Black Hat USA 2026 conference suggests that artificial intelligence is increasing the speed and scale of cybersecurity activity without replacing the attack methods defenders already face.

  • digital brain with network connections

    Microsoft Moving to Internally Developed AI Models in Office Apps

    Microsoft is reportedly using its own in-house artificial intelligence models to handle some workloads in Excel and Outlook, offering new evidence that the company is moving its AI strategy beyond model development and into large-scale cost reduction.