Back to articles
AI Safety

Microsoft Disrupts EvilTokens, an AI-Assisted Account-Takeover Platform

3 min read

Introduction: Generative AI is becoming more than a way to write convincing phishing messages. In the EvilTokens case, it served as an analysis and decision layer inside a broader criminal workflow. Microsoft says the subscription-based platform helped criminals compromise Microsoft accounts at scale, then quickly identify opportunities for payment diversion and business email fraud.

Key points

  • A packaged criminal service: Introduced through a Telegram channel in February, EvilTokens reportedly charged an initial $1,500 fee followed by $500 per month. It brought together bulk spam delivery, phishing pages, account access and post-compromise mailbox analysis.
  • Abuse of device-code authentication: The attackers took advantage of an OAuth flow designed for televisions and other devices with limited input capabilities. After a victim clicked a malicious link or attachment, a hidden script generated a code for an attacker-controlled device and directed the victim to Microsoft’s legitimate device-login page to enter it.
  • AI-assisted reconnaissance: The platform could process as many as 5,000 compromised emails at once. It looked for employees authorized to move substantial funds, their managers and business situations that could support a convincing request to transfer money to an attacker-controlled account.
  • A broad victim base: Microsoft said the operation compromised about 12,000 customer accounts belonging to 10,000 organizations over a period of several months. Victims included organizations in wholesale distribution, construction, financial services, real estate, higher education and healthcare. The largest concentration was in the United States, followed by Canada, the United Kingdom, Australia, India and France.
  • A coordinated disruption: Using legal action and a network of partners, Microsoft seized 50 websites and another 150 domains associated with the service. London’s Metropolitan Police arrested two men on suspicion of offenses allegedly connected to the platform; the arrests do not by themselves establish guilt.

Why it matters

Compromising an inbox has traditionally been only the beginning of an attack. Criminals still had to inspect conversations, map reporting lines, identify suppliers and understand payment procedures. EvilTokens attempted to standardize that work. The result is a shorter path from stolen access to a tailored fraud attempt, especially when the mailbox contains years of business correspondence.

Microsoft’s warning is therefore practical: organizations should assume that attackers can understand the contents of a compromised inbox in minutes, not days. Identity protection remains important, but it is not sufficient on its own. Companies should independently verify requests to change bank details, redirect funds or approve unusual transactions through a trusted second channel. They should also review suspicious device registrations, OAuth activity and sign-ins that users did not initiate.

The case highlights a broader AI-safety problem. The danger does not necessarily come from a standalone model producing an obviously harmful answer. It can emerge when an AI capability is embedded in a complete operational stack that includes phishing delivery, identity abuse and automated targeting. A model that summarizes inboxes and recommends persuasive scenarios may dramatically reduce the expertise required to conduct business email compromise.

That changes the defensive challenge from blocking individual messages to disrupting an ecosystem. Identity providers, security companies, hosting providers, law enforcement and affected organizations need to share indicators and act quickly against infrastructure. EvilTokens also shows why device-code authentication deserves careful user education: a person should never enter a code supplied by someone else unless they intentionally initiated that login.

Source: Ars Technica AI

Comments

Checking sign-in status...

Loading comments...

Related articles