AI Platform Behind 12,000 E-mail Breaches Shut Down

Microsoft has disrupted EvilTokens, a cybercrime service that used AI to help attackers break into e-mail accounts, study their victims, and build convincing financial scams.

The platform moved quickly. Since launching in February, EvilTokens had been tied to more than 12,000 compromised inboxes across over 10,000 organizations worldwide, according to Microsoft. Its victims included businesses and institutions in financial services, healthcare, construction, real estate, wholesale distribution, and higher education.

Microsoft and its partners seized 50 websites used to operate EvilTokens and disabled more than 150 additional domains supporting the service. The Metropolitan Police Service in the United Kingdom also arrested two men on Sept. 11 in connection with the alleged operation.

At the center of EvilTokens was an AI chatbot designed specifically for cybercrime. Once attackers gained access to an inbox, the chatbot could analyze messages, map relationships, identify employees involved in payments, and recommend ways to impersonate trusted contacts.

Microsoft said the platform helped criminals determine "who to target, who to impersonate," and how to get the most money from a compromised organization.

Business e-mail compromise has traditionally required attackers to manually comb through messages, learn how an organization handles payments, and find the right person to impersonate. However, EvilTokens simplified the entire process by automating much of that work.

The tools could quickly sort through a stolen inbox, summarize or translate messages, find invoices and wire-transfer discussions, and identify the people who moved money. EvilTokens could then draft messages that sounded like they came from the victim. It packaged all of this with mailbox access, phishing tools, management dashboards, and even customer support.

The service was sold through Telegram for a $1,500 startup fee, followed by a $500 monthly subscription. Microsoft's complaint also described a bulk e-mail tool that cost $600 a month and a more advanced e-mail delivery platform priced at $1,000 a month.

To break into a target, EvilTokens relied on device-code phishing. Victims were sent to a real Microsoft sign-in page and persuaded to enter an authentication code. The login process looked legitimate because it was, but the code quietly authorized a session controlled by the attacker.

That also made cleanup more complicated. The attackers stole OAuth tokens and authenticated sessions instead of passwords, so a password reset alone might not remove their access. Administrators also needed to revoke the stolen tokens and active sessions.

According to Microsoft's complaint,  EvilTokens used fake Microsoft 365 security notices and other branded templates to direct users into the device authentication flow. Once inside, attackers could use Microsoft Graph and other APIs to search and monitor a mailbox.

The company also found that AI played a role in creating EvilTokens itself. Investigators said much of the platform appeared to have been "vibe coded," with its developers using AI to quickly build and expand the service. EvilTokens reportedly drew on multiple AI models, including improperly integrated services from Groq and OpenAI.

Microsoft and Health-ISAC filed a civil lawsuit in the U.S. District Court for the Eastern District of Virginia against Felix Utomi, Waidi Segun Adams, and five unnamed defendants. The complaint alleges violations of the Computer Fraud and Abuse Act, Electronic Communications Privacy Act, Lanham Act and federal racketeering law.

The court authorized Microsoft to take control of or disable domains connected to the operation. Microsoft worked with Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, the Shadowserver Foundation, and TRM Labs on the disruption. Health-ISAC joined the case because healthcare organizations were among the targets.

This marks the Microsoft Digital Crimes Unit's 40th court-authorized disruption and its first targeting an end-to-end, AI-enabled cybercrime service.

EvilTokens' infrastructure may be offline, but the model behind it is unlikely to disappear. The operation showed how AI can turn a stolen inbox into an immediately useful fraud playbook, allowing less-experienced criminals to launch attacks that once required considerable time and skill.

For more information, read the Microsoft blog post.

About the Author

Chris Paoli (@ChrisPaoli5) is the associate editor for Converge360.

Featured