Microsoft said Tuesday it led an industry disruption of EvilTokens, a subscription phishing platform that used an AI chatbot to compromise 12,000 Microsoft accounts across 10,000 organizations in the months since it launched in February 2026. The service charged a $1,500 initial fee and $500 a month, sold through a Telegram channel, and packaged nearly every step of a business-email-compromise attack into a single automated workflow. Microsoft, working with a legal process and industry partners, seized 50 websites and 150 additional domains tied to the operation, and the UK Metropolitan Police Service arrested two men in connection with the platform.
The scale is the story. Victim organizations spanned wholesale distribution, construction, financial services, real estate, higher education, and healthcare, with the largest concentration in the United States and the next-largest counts in Canada, the United Kingdom, Australia, India, and France. Analyzing 5,000 compromised emails at a time, the platform identified which employees held authority to move money, mapped who they reported to, and generated the pretexts most likely to work on each target.
That inbox-analysis engine is what separates EvilTokens from a decade of prior phishing kits.
“At the center of the service was an AI-style chatbot that could analyze a victim's inbox and help criminals identify trusted relationships, payment authorizations, and sensitive responsibilities.”— Microsoft, Company statement
Key facts
- 01Microsoft said EvilTokens users compromised 12,000 accounts across 10,000 organizations before the takedown.
- 02The platform charged $1,500 upfront and $500 a month, sold through a Telegram channel launched in February 2026.
- 03Microsoft seized 50 websites and 150 additional domains; the UK Metropolitan Police Service arrested two men.
- 04The chatbot analyzed 5,000 compromised inboxes at a time to identify payment-authorized employees and draft impersonation lures.
- 05US organizations were hit hardest, followed by Canada, the UK, Australia, India, and France.
Microsoft described the chatbot as the center of the service, not a bolt-on feature. It read compromised inboxes for trusted relationships, payment authorizations, and sensitive responsibilities, then recommended fraud strategies, including messages that impersonated known contacts. The platform effectively compressed the reconnaissance step of a business-email-compromise attack from days of manual work into a query.
Access was obtained through a legitimate OAuth flow known as device code authentication, designed for TVs and other input-constrained devices that cannot handle a standard login. Users clicking on links in EvilTokens spam were routed to a page running a hidden Node.js automation script that talked in real time to Microsoft Entra, the identity provider, generating a device code for an attacker-controlled device. Victims were then shown the code and instructed to paste it into the official Microsoft device login portal, completing enrollment for the attacker without ever touching a fake login page.
The Node.js backend logic let the operation sidestep signature- and pattern-based detection, and the dashboard let subscribers tailor lures to the target organization's profile. SpyCloud, the security firm that assisted the disruption, confirmed the identity-provider abuse traced back to Entra tokens rather than credential theft, which is part of why traditional defenses missed it.
Microsoft framed the case as a shift in the economics of post-compromise fraud. Previously, an attacker who breached a mailbox still needed hours or days to piece together the organization's management chart, its vendors, its outstanding invoices, and the timing windows when a fund-transfer request would look normal. EvilTokens did that work automatically for every mailbox it ingested, at $500 a month.
“For organizations, the lesson is: assume that once an inbox is compromised, criminals may understand its contents in minutes, not days.”— Microsoft, Company statement
The company's guidance to customers was blunt: strong identity protections and monitoring remain essential, but organizations should independently verify requests to change payment information, redirect funds, or approve unusual transactions through a trusted second channel. In other words, out-of-band confirmation is now the control that matters most, because the in-band context an attacker can fabricate is close to indistinguishable from the real thing.
The takedown is a meaningful hit, but the model it disrupted will be rebuilt. The barriers to launching a copycat are low: an off-the-shelf LLM, a Telegram sales channel, a device-code phishing chain, and a subscriber base of a few hundred customers pays for the infrastructure many times over. Two arrests and 200 seized domains do not change the underlying math.
For security teams, the EvilTokens case is the clearest signal yet that generative AI has crossed from theoretical phishing accelerant into a productized criminal service with measurable victim counts. The defensive playbook has to assume the attacker knows the org chart, the vendor list, and the language of internal approval emails within minutes of gaining a foothold. Every finance and treasury workflow that relies on email as the source of truth for a payment instruction is now the weakest link in the enterprise, and the vendors selling agentic email assistants to legitimate customers are, functionally, in an arms race with the vendors selling them to criminals.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




