Key facts
- Microsoft disrupted the EvilTokens scam platform, which used an AI chatbot.
- The platform compromised 12,000 Microsoft accounts across 10,000 organizations globally.
- EvilTokens charged an initial $1,500 fee and a recurring $500 monthly fee.
- The AI chatbot helped identify trusted relationships and sensitive circumstances for fraud.
- Microsoft seized 50 websites and 150 domains associated with EvilTokens.
- Two men were arrested in the UK in connection with the platform.
Microsoft announced Tuesday that it led an industry-wide effort to disrupt EvilTokens, a subscription-based platform that leveraged an AI chatbot to compromise approximately 12,000 Microsoft accounts over a few months. The platform, introduced via a Telegram channel in February, charged an initial $1,500 fee and a recurring $500 monthly fee.
EvilTokens provided a service to streamline the process of compromising email accounts in large numbers. According to Microsoft, the AI-style chatbot at the platform's core could analyze a victim's inbox to identify trusted relationships, payment authorizations, and sensitive responsibilities, thereby pinpointing circumstances where fraud was most likely to succeed. The platform also recommended fraud strategies and drafted messages impersonating trusted contacts to trick victims into transferring funds.
Microsoft stated that the compromised accounts belonged to 10,000 organizations globally, with the highest concentration in the US, followed by Canada, the UK, Australia, India, and France. Victim organizations spanned sectors including wholesale distribution, construction, financial services, real estate, higher education, and healthcare. SpyCloud, a security firm, provided assistance in the operation and has shared further details on victims.
Through legal processes and a network of partners, Microsoft seized 50 websites and 150 additional domains used by EvilTokens. The UK's Metropolitan Police Service arrested two men in connection with offenses allegedly linked to the crime platform. The account compromises were reportedly achieved using a legitimate OAuth process known as device code authentication, designed for devices lacking standard login interfaces.
