Tuesday, September 22, 2026
Tech Beat
Sep 22, 2026, 7:45 PMCybersecurity

Microsoft Disrupts EvilTokens AI Scam After 12,000 Account Breaches

Microsoft seized 50 sites and 150 domains tied to EvilTokens, an AI scam service blamed for breaching 12,000 accounts at 10,000 organizations worldwide.

Listen to this briefingAudio briefing

Summary

On September 22, 2026, Microsoft said it led an industry-wide disruption of EvilTokens, an AI-assisted subscription platform whose customers compromised 12,000 Microsoft accounts at 10,000 organizations within a few months. Microsoft used legal action and industry partners, including SpyCloud, to seize 50 websites and 150 additional domains. The UK Metropolitan Police arrested two men on suspicion of connected offenses. Launched through Telegram in February, EvilTokens charged $1,500 initially and $500 monthly. Victims were concentrated in the US, followed by Canada, the UK, Australia, India and France, across wholesale distribution, construction, financial services, real estate, higher education and healthcare.

EvilTokens automated spam and abused legitimate OAuth device code authentication intended for input-constrained devices. Malicious links or attachments opened a page whose hidden script interacted with Microsoft Entra to generate a code enrolling an attacker-controlled device. Victims entered that code into Microsoft’s official device login portal, while Node.js backend logic evaded signature-based and pattern-based detection. A customizable dashboard and AI chatbot analyzed 5,000 compromised emails at once, mapped trusted relationships and payment authority, identified lucrative targets, and drafted impersonation messages designed to redirect funds. Microsoft warned that criminals can now understand compromised inboxes in minutes rather than days, urging strong identity monitoring and independent verification of payment changes or unusual transactions through a trusted second channel.

Positives

  • Microsoft seized 50 websites and 150 additional domains used to operate EvilTokens through legal action and industry partnerships.
  • The UK Metropolitan Police arrested two men on suspicion of offenses allegedly connected to EvilTokens.
  • SpyCloud assisted Microsoft’s disruption operation and helped identify details about affected organizations.
  • Microsoft advised organizations to verify payment changes and unusual transactions through a trusted second channel.

Risks & concerns

  • EvilTokens customers compromised 12,000 Microsoft accounts belonging to 10,000 organizations worldwide within a few months.
  • The AI chatbot analyzed 5,000 compromised emails simultaneously to identify payment authority, trusted relationships and high-value targets.
  • EvilTokens industrialized account fraud for a $1,500 initial fee plus a recurring $500 monthly charge.
  • Hidden scripts and Node.js logic abused OAuth device authentication while bypassing signature-based and pattern-based detection.
  • Victims spanned six named countries and sectors including finance, healthcare, higher education, construction and real estate.
Primary sourceAI - Ars Technicahttps://arstechnica.com/security/2026/09/microsoft-disrupts-ai-assisted-platform-that-compromised-12000/
Read full article
Editorial note: Tech Beat summarizes and analyzes third-party reporting. The source link is the authoritative article. This page does not reproduce the full source text.

More From The Wire

CybersecuritySep 22

ShinyHunters Claims FBI Breach Exposed Agents and Applicants

CybersecuritySep 22

SpyCloud Finds Stolen Passwords Expose 1,787 US Water Organizations

CybersecuritySep 21

Meta Muse Zero-Day Lets Any Mac App Hijack the AI Assistant