Microsoft Takes Down EvilTokens, an AI Service Built for Email Fraud

The court-authorized operation removed infrastructure behind a service that Microsoft says turned compromised email accounts into maps for impersonation and payment scams.

By 4 min read
Microsoft Takes Down EvilTokens, an AI Service Built for Email Fraud
Microsoft Takes Down EvilTokens, an AI Service Built for Email Fraud

Listen to this story

The audio brief

About 1:45
0:001:45
Read transcript
Microsoft has seized 50 websites and disabled more than 150 related domains in a court-authorized operation against EvilTokens, an alleged cybercrime service that turned stolen email access into ready-made fraud plans. Two men in the United Kingdom were also arrested on September 11 and released on police bail while the investigation continues. Microsoft says EvilTokens used an AI-style chatbot to analyze compromised inboxes, find wire-transfer discussions, identify people who move money, and recommend trusted contacts to impersonate. That matters because business-email fraud often depends less on writing a convincing message than on understanding who approves payments, which invoices are real, and how money normally moves. The alleged entry point was device-code phishing. Victims entered an authentication code on Microsoft’s legitimate sign-in page, allowing attackers to access accounts without obtaining a password. Microsoft warns that changing the password may not be enough if active sessions and access tokens remain in place. The service reportedly launched in February 2026, reached more than 12,000 inboxes across over 10,000 organizations, and was sold through Telegram for a $1,500 initiation fee plus $500 a month. Microsoft says it used AI assistance and supported targets in sectors from finance and healthcare to real estate and construction. The operation involved Microsoft, the U.S. District Court for the Eastern District of Virginia, and technology and security partners. But infrastructure can be removed faster than the playbook disappears. The key constraint now is whether organizations can detect persistent inbox access and independently verify payment changes through a trusted second channel.

Story brief

3 key points

Microsoft and partners dismantled EvilTokens after a U.S. court authorized the seizure of 50 operating websites and disruption of more than 150 related domains. The alleged service turned stolen inbox access into structured business-email-fraud campaigns, reportedly identifying payment workflows, decision-makers and impersonation targets. Microsoft linked it to over 12,000 compromised inboxes across 10,000-plus...

  1. 01

    EvilTokens reportedly charged a $1,500 initiation fee plus $500 monthly for a packaged criminal workflow.

  2. 02

    Attackers allegedly used device-code phishing; password resets alone might not remove access if sessions and tokens remain active.

  3. 03

    Microsoft said the service analyzed inboxes for wire transfers, money movers and trusted contacts to impersonate.

Microsoft and a group of technology and law-enforcement partners have disrupted EvilTokens, an alleged cybercrime service that used an AI-style chatbot to turn compromised email inboxes into tailored fraud plans. The action seized 50 operating websites and disabled more than 150 associated domains under a U.S. court order.

Microsoft’s account describes a service built to automate the slow, investigative part of business-email fraud. Rather than merely helping an attacker draft a persuasive message, EvilTokens could analyze a victim’s mailbox, map organizational roles, surface payment conversations and identify trusted relationships. It could then recommend people to impersonate and targets for fraud.

From a sign-in trick to a fraud roadmap

The alleged entry point was a device-code phishing attack. Victims were tricked into entering an authentication code on Microsoft’s legitimate sign-in page, giving criminals access without handing over a password. Microsoft said that access could remain after a password reset if associated sessions and tokens were not also revoked.

Once inside, the service’s alleged value was speed and structure. A criminal who had obtained access no longer needed to manually sift through thousands of messages to find decision-makers, invoices or payment procedures. Microsoft said preset prompts could locate wire-transfer discussions, identify people who move money and suggest the best contacts to impersonate.

Screenshot of an EvilTokens interface showing AI analysis of scanned organizational emails and suggested targets.
Microsoft published this image as an example of EvilTokens’ alleged inbox analysis and suggested follow-up prompts. Source: blogs.microsoft.com.

A subscription product for a criminal workflow

Microsoft said EvilTokens was sold through Telegram for a $1,500 initiation fee and a recurring $500 subscription. Investigators also found evidence that large parts of the platform had been built with AI assistance and that it drew on capabilities from multiple AI models. The service paired those tools with dashboards, support and fraud-focused features in what Microsoft characterized as a commercially run operation.

That packaging is central to the risk Microsoft identifies: expertise once spread across identity attacks, cloud systems, social engineering and financial fraud was presented through a ready-made interface. The company said the platform affected organizations across sectors including financial services, real estate, higher education, healthcare, construction and wholesale distribution.

The takedown paired civil action with arrests

The U.S. District Court for the Eastern District of Virginia authorized the disruption. Microsoft and Health-ISAC worked with Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation and TRM Labs against parts of the service, while Microsoft said it notified affected customers and helped remediate compromised accounts.

In the United Kingdom, Metropolitan Police arrested two men, ages 32 and 38, on September 11 on suspicion of offenses connected with the alleged EvilTokens operation. Both were released on police bail subject to conditions while the investigation continues. Microsoft called the case its Digital Crimes Unit’s first court-authorized action against an end-to-end AI-enabled cybercrime service.

The remaining problem is the inbox itself

Removing a service’s infrastructure does not remove the underlying playbook. Microsoft’s practical warning is that a compromised inbox may now be understood in minutes rather than days. Its advice is to use strong identity protections and independently verify requests to change payment information, redirect funds or approve unusual transactions through a trusted second channel.

Editorial analysis

Our Read

EvilTokens is notable less for a novel way to steal access than for what allegedly came next: turning an inbox into a guided fraud workflow. Microsoft says the service linked account compromise, mailbox analysis and target selection in one subscription product. That can make a familiar security failure more consequential, because an attacker need not spend days learning who approves payments or which vendors matter. The key event to watch is whether the legal seizure and arrests meaningfully interrupt that packaged model, or merely displace it to new infrastructure.

Sources

  1. blogs.microsoft.comDisrupting EvilTokens: The AI Chatbot Built for Cybercrime - Microsoft On the Issues

Loading discussion...

YOUR READING SPACE

Notifications