AI NewsInfrastructureAnnouncement
Microsoft seized 200 domains behind EvilTokens, an AI chatbot service that read compromised inboxes and picked fraud targets
Microsoft's Digital Crimes Unit and partners disrupted EvilTokens, a $1,500 subscription service that used an AI chatbot to read compromised Microsoft mailboxes and pick employees to impersonate for wire fraud, and seized 50 websites and 150 supporting domains.

Image: Microsoft
Why it mattersA compromised inbox now yields a fraud plan in minutes rather than days, so any process that trusts an email request to move money needs a second channel confirming it before the transfer.
A compromised email inbox used to give an attacker a pile of email to read. It now gives them a chatbot that reads the pile and picks the right person to impersonate for a wire transfer. Microsoft says it disrupted a subscription service that packaged exactly that, called EvilTokens, in a coordinated operation announced on 22 September 2026 by Steven Masada of Microsoft's Digital Crimes Unit.
According to Microsoft, EvilTokens launched in February 2026, was sold on Telegram for a $1,500 initiation fee and a $500 monthly subscription, and had been linked within months to 12,000 compromised inboxes across 10,000 organizations. Microsoft observed the highest concentration of victim activity in the United States, followed by Canada, the United Kingdom, Australia, India and France. Named sectors ranged from wholesale distribution and construction to financial services, real estate, higher education and healthcare.
How the access worked
Microsoft says the service abused a standard OAuth flow called device code authentication, the one designed for televisions and other devices with no keyboard. Victims clicked a link and were shown a code with instructions to enter it on Microsoft's real sign-in page. Completing that page enrolled the attacker's device against the victim's account, without any password ever being revealed. Access could persist after a password reset if the associated sessions and tokens were not also revoked. SpyCloud, one of the firms assisting the disruption, identified the affected identity provider as Microsoft Entra.
What the chatbot did once inside
Once an inbox was open, EvilTokens automated the reconnaissance an attacker used to do by hand. According to Microsoft, the platform's AI tools summarized and translated emails, surfaced financial conversations, mapped organizational roles, and named potential targets. Preset prompts offered to find wire-transfer discussions, identify the organization's "money movers", locate vendor invoices, and pick the best people to impersonate. The chatbot then drafted follow-up messages that carried a plausible ruse for tricking an employee into moving money to an attacker-controlled account. Microsoft's investigators also say large portions of the EvilTokens platform itself were "vibe coded" using AI.
The disruption itself
With authorization from the U.S. District Court for the Eastern District of Virginia, Microsoft and the non-profit Health-ISAC, joined by Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation and TRM Labs, seized 50 websites operating the service and disabled 150 more supporting domains. In the United Kingdom, the Metropolitan Police Service's cybercrime team arrested two men, aged 32 and 38, on 11 September 2026 and seized digital devices. Both were released on police bail while the investigation continues. Microsoft says this is its Digital Crimes Unit's 40th court-authorized disruption and its first against an end-to-end AI-enabled cybercrime service.
Microsoft's own advice, quoted in the Ars Technica report on the disruption: "assume that once an inbox is compromised, criminals may understand its contents in minutes, not days," and treat any request to change payment information, redirect funds, or approve an unusual transaction as something to independently verify through a trusted second channel. For a team building software, that means the payment-approval flow, the vendor-change flow, the password-reset-approval message and every out-of-band alert that could impersonate a colleague are now the security surface. A signed request that arrives from a real logged-in session is no longer evidence that a human sent it.
Source
Primary: Disrupting EvilTokens: The AI Chatbot Built for Cybercrime on Microsoft On the Issues, by Steven Masada, 22 September 2026. Reported by Dan Goodin in Microsoft disrupts AI-assisted platform that compromised 12,000 accounts at Ars Technica.
This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.
Get AI News in your inbox
New developer tools, model and agent releases, and how teams are actually using them to release software. Short, and only when there is something worth reading.


