Story
September 23, 2026
EvilTokens Turned Stolen Inboxes Into Fraud Playbooks in Hours
Microsoft’s takedown of EvilTokens exposes an AI-assisted phishing operation that allegedly compromised 12,000 accounts and rapidly converted inbox access into tailored payment scams. The disruption may slow the service, but it underscores how AI is accelerating familiar fraud.
EvilTokens emerged in February as a subscription phishing service, offering criminals an unusually streamlined route from a deceptive email to a compromised Microsoft account. The platform charged a $1,500 entry fee and $500 a month, packaging device-code phishing with automated spam campaigns and tailored lures.1
The initial breach exploited a legitimate OAuth flow intended for televisions and other devices with limited input. Victims were pushed to a convincing page, shown a device code and instructed to enter it on Microsoft’s real sign-in portal — unknowingly authorizing an attacker-controlled device. Once inside, EvilTokens could process as many as 5,000 emails at a time, identifying people who could move money, their managers, trusted contacts and plausible pretexts for a payment request.
Microsoft’s central warning is about speed. “Assume that once an inbox is compromised, criminals may understand its contents in minutes, not days,” the company said, urging organizations to verify altered payment instructions and unusual transactions through a separate trusted channel.1
That speed is the case’s broader significance. Axios reported that the platform’s chatbot condensed work that might have taken attackers days into hours — while evidence suggested “large portions” of EvilTokens itself were built with AI tools. In Microsoft’s framing, the technology lowered the barrier twice: first to constructing malicious tooling, then to turning stolen access into credible fraud.2
Microsoft says the operation compromised more than 12,000 accounts across 10,000 organizations, with victims concentrated in the United States and also reported in Canada, the UK, Australia, India and France. Targets spanned construction, finance, real estate, education and healthcare.2
The response came after months of tracking. Using court-authorized legal action and partner support, Microsoft seized 50 EvilTokens websites and disrupted more than 150 related domains; London’s Metropolitan Police arrested two men, aged 32 and 38, in connection with the platform. The takedown cuts off key infrastructure, but not the lesson: inbox security and independent payment checks now have to assume that attackers can read an organization’s relationships at machine speed.1