Microsoft Disrupts EvilTokens AI Scam After 12,000 Account Breaches
Microsoft seized 50 sites and 150 domains tied to EvilTokens, an AI scam service blamed for breaching 12,000 accounts at 10,000 organizations worldwide.
Summary
On September 22, 2026, Microsoft said it led an industry-wide disruption of EvilTokens, an AI-assisted subscription platform whose customers compromised 12,000 Microsoft accounts at 10,000 organizations within a few months. Microsoft used legal action and industry partners, including SpyCloud, to seize 50 websites and 150 additional domains. The UK Metropolitan Police arrested two men on suspicion of connected offenses. Launched through Telegram in February, EvilTokens charged $1,500 initially and $500 monthly. Victims were concentrated in the US, followed by Canada, the UK, Australia, India and France, across wholesale distribution, construction, financial services, real estate, higher education and healthcare.
EvilTokens automated spam and abused legitimate OAuth device code authentication intended for input-constrained devices. Malicious links or attachments opened a page whose hidden script interacted with Microsoft Entra to generate a code enrolling an attacker-controlled device. Victims entered that code into Microsoft’s official device login portal, while Node.js backend logic evaded signature-based and pattern-based detection. A customizable dashboard and AI chatbot analyzed 5,000 compromised emails at once, mapped trusted relationships and payment authority, identified lucrative targets, and drafted impersonation messages designed to redirect funds. Microsoft warned that criminals can now understand compromised inboxes in minutes rather than days, urging strong identity monitoring and independent verification of payment changes or unusual transactions through a trusted second channel.
Positives
- Microsoft seized 50 websites and 150 additional domains used to operate EvilTokens through legal action and industry partnerships.
- The UK Metropolitan Police arrested two men on suspicion of offenses allegedly connected to EvilTokens.
- SpyCloud assisted Microsoft’s disruption operation and helped identify details about affected organizations.
- Microsoft advised organizations to verify payment changes and unusual transactions through a trusted second channel.
Risks & concerns
- EvilTokens customers compromised 12,000 Microsoft accounts belonging to 10,000 organizations worldwide within a few months.
- The AI chatbot analyzed 5,000 compromised emails simultaneously to identify payment authority, trusted relationships and high-value targets.
- EvilTokens industrialized account fraud for a $1,500 initial fee plus a recurring $500 monthly charge.
- Hidden scripts and Node.js logic abused OAuth device authentication while bypassing signature-based and pattern-based detection.
- Victims spanned six named countries and sectors including finance, healthcare, higher education, construction and real estate.