← All posts / Meta

AI at Every Step of the Attack: Inside Microsoft's EvilTokens Takedown

Microsoft's Digital Crimes Unit has disrupted EvilTokens, the first end-to-end AI-enabled cybercrime service — 12,000 compromised inboxes, 10,000 organizations, and two arrests in London.

AI at Every Step of the Attack: Inside Microsoft's EvilTokens Takedown

On Tuesday, September 22, 2026, Microsoft’s Digital Crimes Unit (DCU) announced the disruption of EvilTokens — a subscription-based cybercrime platform that the company describes as its first court-authorized takedown of an end-to-end AI-enabled cybercrime service. The case is a landmark not because of the volume of victims, though that volume is substantial, but because of what the platform actually did: artificial intelligence was woven into every step of the attack chain, from compromising the email account to planning the fraud that followed.

What EvilTokens was

At its core, EvilTokens was a phishing-as-a-service operation built around a deceptively simple trick: the OAuth 2.0 device code authentication flow. Instead of trying to steal passwords, attackers induced victims to enter an authentication code on Microsoft’s own legitimate sign-in page. Once the victim completed what looked like a normal sign-in, the criminals held a valid session — access that could persist even after a password reset, unless sessions and tokens were also revoked.

Launched in February 2026, the service grew with alarming speed. Microsoft linked it to more than 12,000 compromised email inboxes across over 10,000 organizations worldwide within just a few months. Victim concentrations were highest in the United States, Canada, the United Kingdom, Australia, India, and France, with affected organizations spanning wholesale distribution, construction, financial services, real estate, higher education, and healthcare.

Access was sold through Telegram for a $1,500 initiation fee plus a recurring $500 monthly subscription — a price point that put industrial-grade account compromise within reach of criminal teams that previously lacked the expertise.

The chatbot that read your inbox

What set EvilTokens apart from ordinary credential-harvesting kits was its centerpiece: an AI-style chatbot designed to sit inside a compromised mailbox and do the analyst work that used to take experienced fraudsters days.

Once inside an account, criminals have traditionally needed time and skill to sift through thousands of messages, identify who holds authority, understand payment processes, and find openings for fraud. EvilTokens automated that reconnaissance. According to Microsoft, its AI tools could:

  • Summarize and translate emails, making foreign-language inboxes immediately usable
  • Surface financial conversations and locate vendor invoices
  • Map organizational roles and identify each organization’s “money movers”
  • Identify trusted relationships — the people whose names carry weight
  • Recommend specific targets and draft impersonation messages tailored to them

Microsoft’s framing is blunt: AI was not simply helping attackers write more convincing emails. It helped them decide who to target, who to impersonate, and how to extract the maximum amount of money from each relationship. Preset prompts included searches for wire-transfer discussions and shortcuts for picking the best person to impersonate. In effect, the platform compressed the entire pre-fraud intelligence cycle — traditionally the domain of specialists in identity attacks, cloud systems, social engineering, and financial fraud — into a ready-made interface with customer support and management dashboards.

Vibe-coded crime, multi-model offense

Two details from the investigation deserve particular attention. First, investigators found evidence that large portions of EvilTokens had been “vibe coded” — built with AI assistance by its own creators, lowering the engineering barrier on the supply side just as the service lowered the skill barrier on the customer side. Second, the platform drew on capabilities from multiple AI models, stitching together frontier capabilities from more than one provider into a single criminal workflow.

The irony of the coalition is hard to miss: Microsoft acted alongside OpenAI, whose models were among those repurposed, together with Cloudflare, Coinbase, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs. Health-ISAC, the global threat-sharing nonprofit for the health sector, joined the legal action as a co-plaintiff because healthcare organizations were among the targets. Authorization came from the U.S. District Court for the Eastern District of Virginia.

Two arrests in London

The disruption combined civil legal action with coordinated operational work. Microsoft and its partners seized 50 websites used to operate the service and disabled more than 150 additional domains tied to its supporting infrastructure. Visitors to the seized infrastructure now see a seizure notice.

On the law enforcement side, Microsoft shared intelligence with the Metropolitan Police Service’s cybercrime team, which took operational action in the UK. On September 11, 2026, officers arrested two men, aged 32 and 38, seizing digital devices for examination. Both have been released on police bail while the investigation continues.

Notably, Microsoft points out that its own investigators used reverse engineering and AI-powered tools to analyze evidence and accelerate the investigation — the same technology class that powered the offense also accelerated the defense. The takedown marks the DCU’s 40th court-authorized disruption in nearly two decades of operations.

Why this matters beyond one takedown

The infrastructure is disrupted, but the blueprint is now public. Microsoft’s 2026 Responsible AI Transparency Report warns that increasingly capable and accessible AI is being used to scale fraud, impersonation, and online abuse — and EvilTokens is the clearest demonstration to date of what that looks like when combined with stolen account access.

The operational lesson Microsoft draws for organizations is stark: assume that once an inbox is compromised, criminals can understand its contents in minutes, not days. The old calculus — that attackers needed time to read through a mailbox, and that detection had a window — no longer holds. Strong identity protections (phishing-resistant MFA, conditional access, token revocation on compromise) remain essential, but they are no longer sufficient on their own.

The second lesson is procedural rather than technical: independently verify any request to change payment information, redirect funds, or approve unusual transactions through a trusted second channel. If an AI can draft a perfect impersonation of your CFO’s supplier email, the only reliable defense is a verification path the AI cannot simulate — a phone call to a known number, a question only the real person can answer.

EvilTokens will not be the last service of its kind. It was, in Microsoft’s words, an early warning of what happens when cybercriminals combine stolen access with AI capable of understanding how an organization works. The 40th DCU disruption closed one chapter; the arms race between AI-enabled fraud and AI-enabled defense is just getting started.