Story
September 23, 2026

EvilTokens Turned Stolen Inboxes Into Fraud Playbooks in Hours

Microsoft and its partners portray EvilTokens as a warning that compromised email is no longer merely an entry point: AI can quickly map trust, authority and payment trails. The case also shows law enforcement and industry moving against the infrastructure, even as the underlying tactics remain widely exploitable.

EvilTokens emerged in February as a subscription phishing service, offering criminals an unusually streamlined route from a deceptive email to a compromised Microsoft account. The platform charged a $1,500 entry fee and $500 a month, packaging device-code phishing with automated spam campaigns and tailored lures.

The initial breach exploited a legitimate OAuth flow intended for televisions and other devices with limited input. Victims were pushed to a convincing page, shown a device code and instructed to enter it on Microsoft’s real sign-in portal — unknowingly authorizing an attacker-controlled device. Once inside, EvilTokens could process as many as 5,000 emails at a time, identifying people who could move money, their managers, trusted contacts and plausible pretexts for a payment request.

Microsoft’s central warning is about speed. “Assume that once an inbox is compromised, criminals may understand its contents in minutes, not days,” the company said, urging organizations to verify altered payment instructions and unusual transactions through a separate trusted channel.

That speed is the case’s broader significance. Axios reported that the platform’s chatbot condensed work that might have taken attackers days into hours — while evidence suggested “large portions” of EvilTokens itself were built with AI tools. In Microsoft’s framing, the technology lowered the barrier twice: first to constructing malicious tooling, then to turning stolen access into credible fraud.

Microsoft says the operation compromised more than 12,000 accounts across 10,000 organizations, with victims concentrated in the United States and also reported in Canada, the UK, Australia, India and France. Targets spanned construction, finance, real estate, education and healthcare.

The response came after months of tracking. Using court-authorized legal action and partner support, Microsoft seized 50 EvilTokens websites and disrupted more than 150 related domains; London’s Metropolitan Police arrested two men, aged 32 and 38, in connection with the platform. The takedown cuts off key infrastructure, but not the lesson: inbox security and independent payment checks now have to assume that attackers can read an organization’s relationships at machine speed.