---
url: "https://www.xcademia.com/news/microsoft-disrupts-eviltokens-ai-powered-cybercrime-platform"
title: "Microsoft Disrupts EvilTokens AI-Powered Cybercrime Platform"
description: "Microsoft says it disrupted EvilTokens, an AI-enabled cybercrime service linked to thousands of compromised email inboxes and organizations worldwide."
publishedAt: "2026-09-23T06:43:14.754+00:00"
updatedAt: "2026-09-23T07:28:22.908869+00:00"
type: news
category: cybersecurity
source_name: Microsoft
source_url: "https://blogs.microsoft.com/on-the-issues/2026/09/22/disrupting-eviltokens-the-ai-chatbot-built-for-cybercrime/"
tags:
  - "#Cybersecurity"
  - "#Microsoft"
  - "#EvilTokens"
  - "#Cybercrime"
  - "#AISecurity"
  - "#Phishing"
  - "#IdentitySecurity"
  - "#DigitalCrimes"
---

# Microsoft Disrupts EvilTokens AI-Powered Cybercrime Platform

> Microsoft says it disrupted EvilTokens, an AI-enabled cybercrime service linked to more than 12,000 compromised email inboxes across over 10,000 organizations, after investigators identified AI-driven tools for account analysis and financial fraud.

Source: **Microsoft** · 23 September 2026

Microsoft says it has disrupted **EvilTokens**, a cybercrime platform that combined compromised email accounts, AI-powered inbox analysis and tools intended to help criminals prepare financial fraud and scams.

According to Microsoft's Digital Crimes Unit, EvilTokens used AI throughout multiple stages of the attack chain. The service could analyze compromised inboxes, identify trusted relationships and payment responsibilities, surface potential fraud opportunities and recommend people to impersonate.

Microsoft says the platform was linked to more than **12,000 compromised email inboxes across more than 10,000 organizations worldwide** within months of launching in February 2026.

The company says victim activity was concentrated in the **United States, Canada, United Kingdom, Australia, India and France**, with affected organizations spanning industries including wholesale distribution, construction, financial services, real estate, higher education and healthcare.

Microsoft says its disruption operation resulted in the seizure of **50 websites** used to operate the service and the disabling of more than **150 additional domains** associated with supporting infrastructure.

In the United Kingdom, the Metropolitan Police Service's cybercrime team arrested two men in connection with the alleged operation.

## 
EvilTokens Used AI Beyond Message Generation

Microsoft's description of EvilTokens highlights a shift from using AI simply to generate convincing phishing or scam messages.

According to the company, the service could help criminals determine:

- Who to target
- Who to impersonate
- Which relationships could be exploited
- Where payment activity was taking place
- Which organisational roles were connected to financial decisions
- Which fraud strategies could potentially produce financial gain

The platform could analyze a victim's inbox and identify trusted relationships, payment authorizations, sensitive responsibilities and other circumstances that could be useful for fraud.

Microsoft says this allowed criminals to move from gaining access to an account toward understanding how an organization operated.

That distinction is central to the company's assessment of the service.

Instead of treating a compromised mailbox simply as a collection of messages, EvilTokens attempted to turn the information inside the mailbox into an operational map for fraud.

## 
How EvilTokens Gained Access to Email Accounts

Microsoft says EvilTokens helped criminals compromise email accounts by tricking victims into entering an authentication code on Microsoft's legitimate sign-in page.

The victim completed what appeared to be the normal authentication process but unknowingly gave the attacker access to the account.

Microsoft says that access could persist even after a password reset if the associated sessions and tokens were not also revoked.

The company refers readers to Microsoft Threat Intelligence for additional technical information about the operation, device-code attacks and defensive measures.

Once an account had been compromised, attackers traditionally needed to manually search through large numbers of emails to find useful information.

That process could involve identifying decision-makers, finding payment discussions, understanding vendor relationships and determining which employees had authority over financial activity.

EvilTokens was designed to automate much of that analysis.

## 
AI Analysis Turned Inbox Data Into Fraud Opportunities

Microsoft says EvilTokens could summarize and translate emails, surface financial conversations, map organizational roles and identify trusted relationships.

The platform also included preset prompts designed to help criminals locate specific types of information.

According to Microsoft, these included prompts to:

- Find wire-transfer discussions
- Identify an organization's "money movers"
- Locate vendor invoices
- Determine people who could be impersonated
- Identify potential financial opportunities

The platform could also recommend fraud strategies and help draft messages designed to impersonate trusted contacts.

This meant the AI component was not limited to summarizing information.

It was positioned as an analytical layer between stolen account access and potential financial exploitation.

### 

![info-1](https://0a515t3ure77wbvx.public.blob.vercel-storage.com/articles/1790145674006-info-1--168---1-.webp)

## EvilTokens Was Sold as a Commercial Service

Microsoft says EvilTokens was sold through Telegram for a **$1,500 initiation fee** and a recurring **$500 subscription**.

The platform combined several capabilities into a single service, including account compromise, mailbox analysis, target selection and fraud preparation.

Microsoft describes the service as having characteristics associated with a commercially operated cybercrime platform.

The company's investigation found evidence that large portions of EvilTokens had been **"vibe coded"**, meaning AI was used to help its creators build parts of the platform.

Microsoft also determined that EvilTokens drew capabilities from multiple AI models.

The result, according to Microsoft, was a service that packaged multiple stages of cyber-enabled financial fraud behind a ready-made interface.

The platform included subscription pricing, customer support, management dashboards and tools intended to move users from account access toward financial exploitation.

## 
EvilTokens Included a Broader Cybercrime Toolset

Microsoft's investigation also identified an EvilTokens store operating through Telegram.

The screenshots published by Microsoft show tools associated with capabilities including token capture, browser access, traffic redirection, email automation, SMTP delivery and email validation.

The company describes these capabilities as part of the broader infrastructure surrounding the service.

The significance of the platform was therefore not limited to its AI chatbot.

Microsoft's account indicates that EvilTokens combined identity-related attacks, account access, mailbox analysis, social engineering and financial fraud preparation within a single service.

## 
AI Lowered Barriers for Both Attackers and Defenders

Microsoft says its investigators found evidence that AI was used in the construction of the EvilTokens platform itself.

At the same time, Microsoft used AI-powered tools during its own investigation.

The Digital Crimes Unit used reverse engineering and AI-assisted analysis to examine evidence, accelerate investigative work and identify infrastructure supporting the service.

This creates a two-sided development described by Microsoft: AI can reduce barriers for cybercriminals while also providing defenders with tools for analyzing increasingly complex cybercrime operations.

The EvilTokens case therefore demonstrates how AI can affect both sides of the cybersecurity ecosystem.

## 
Microsoft Coordinated a Multi-Organization Disruption

Microsoft says no single organization could disrupt EvilTokens alone because the service relied on multiple infrastructure and service providers.

The disruption involved civil legal action combined with operational coordination across technology companies, cybersecurity organizations and law enforcement.

Because healthcare organizations were among the targeted entities, **Health-ISAC** joined Microsoft's legal action as a co-plaintiff.

With authorization from the **U.S. District Court for the Eastern District of Virginia**, Microsoft and Health-ISAC worked with:

- Cloudflare
- Coinbase
- OpenAI
- Railway
- SpyCloud
- The Shadowserver Foundation
- TRM Labs

Microsoft says the organizations acted against key parts of the infrastructure supporting EvilTokens.

The company also says it notified affected customers, helped remediate compromised accounts and shared intelligence for additional defensive and investigative activity.

### 

![info-2](https://0a515t3ure77wbvx.public.blob.vercel-storage.com/articles/1790145690109-info-2--150-.webp)

## UK Police Arrest Two Men

Microsoft says its investigation also supported operational action by the UK's Metropolitan Police Service cybercrime team.

According to Microsoft, investigators shared intelligence with specialist officers, who arrested two men in the United Kingdom on **September 11, 2026**.

The individuals were reported as being **32 and 38 years old**.

Microsoft says police seized digital devices and other items for examination.

Both men have been released on police bail subject to conditions while the investigation continues.

These are allegations and an ongoing investigation. The arrests should not be interpreted as a final determination of criminal liability.

## 
50 Websites Seized and More Than 150 Domains Disabled

Microsoft says the disruption resulted in the seizure of **50 websites** used to operate EvilTokens.

The company also says more than **150 additional domains** connected to supporting infrastructure were disabled.

A domain-seizure notice published with the article displays Microsoft and partner organizations involved in the operation.

The infrastructure action was designed to interfere with the service's ability to operate and support customers.

Microsoft's announcement does not indicate that every component of the broader cybercrime ecosystem has been permanently eliminated.

Instead, the company frames the operation as a disruption of the EvilTokens platform and the infrastructure supporting it.

## 
Microsoft's Digital Crimes Unit Marks Its 40th Court-Authorized Disruption

Microsoft says the EvilTokens operation represents the **40th court-authorized disruption** carried out by its Digital Crimes Unit.

The company says these operations span nearly two decades of activity targeting cyber threat actors, malicious tools and supporting infrastructure.

Microsoft also describes EvilTokens as the DCU's **first action against an end-to-end AI-enabled cybercrime service**.

That distinction is significant within the context of Microsoft's own cybercrime-disruption program.

The company is not describing EvilTokens simply as a conventional phishing operation that happened to use AI.

Instead, Microsoft says AI was integrated into multiple stages of the service, from platform development and inbox analysis to target selection and fraud preparation.

### 

![info-3](https://0a515t3ure77wbvx.public.blob.vercel-storage.com/articles/1790145706935-info-3--140-.webp)

## What EvilTokens Reveals About AI-Enabled Cybercrime

Microsoft says the infrastructure supporting EvilTokens has been disrupted, but argues that the broader model demonstrated by the service could continue to appear elsewhere.

The company's **2026 Responsible AI Transparency Report** states that increasingly capable and accessible AI is being used to scale fraud, impersonation and other forms of online abuse.

EvilTokens provides one example of how compromised access can be combined with AI to accelerate the process of understanding an organization and preparing fraudulent activity.

The important distinction is the combination of capabilities.

A stolen mailbox already contains information about an organization's people, processes and communications.

AI can potentially make that information easier to search, summarize, classify and connect.

In Microsoft's description of EvilTokens, the service used that capability to identify relationships, financial discussions and potential targets.

This reduces the amount of manual analysis required after an account is compromised.

## 
The Risk Extends Beyond Phishing Messages

A common discussion around AI-enabled cybercrime focuses on the ability to generate more convincing phishing messages.

Microsoft's EvilTokens investigation points to a broader issue.

The AI system described by Microsoft could help attackers analyze the information they had already obtained and decide how to use it.

That creates several distinct stages:

**Access:** Obtain access to an account.

**Understanding:** Analyze the organization's communications and relationships.

**Targeting:** Identify people and processes connected to financial activity.

**Impersonation:** Determine who could be convincingly impersonated.

**Fraud preparation:** Develop a strategy for persuading a victim to take an action.

The AI component therefore operated as an analysis and decision-support layer for criminals, according to Microsoft's findings.

That is different from using AI solely as a writing assistant.

## 
What Organizations Can Learn From the EvilTokens Case

Microsoft's recommended defensive lesson is that organizations should assume a compromised inbox can be analyzed quickly.

The company says strong identity protection and monitoring remain important.

It also recommends independently verifying requests involving:

- Changes to payment information
- Redirection of funds
- Unusual financial transactions
- Other sensitive financial actions

Microsoft recommends using a trusted second communication channel to verify these requests.

The recommendation addresses a key risk exposed by the EvilTokens case: an attacker with access to legitimate email conversations may have enough contextual information to make a fraudulent request appear consistent with normal business activity.

Independent verification provides a separate control outside the compromised communication channel.

## 
The Broader Security Implication

The announcement highlights a broader industry shift toward AI being integrated into both offensive and defensive cybersecurity workflows.

For attackers, Microsoft's investigation suggests that AI can help automate parts of the process that previously required significant manual effort and domain knowledge.

For defenders, the same technologies can assist with reverse engineering, evidence analysis and infrastructure discovery.

This creates an increasingly important need for organizations to defend not only authentication systems but also the business processes that follow a successful account compromise.

Identity security, session and token management, mailbox monitoring and independent financial verification can become interconnected controls when attackers are able to analyze compromised information at scale.

## 
Final Takeaway

Microsoft says it disrupted EvilTokens, a cybercrime service that combined compromised email accounts with AI-powered analysis and fraud preparation.

The company links the service to more than **12,000 compromised inboxes across over 10,000 organizations** and says its operation seized **50 websites** and disabled more than **150 additional domains**.

The case also involved coordinated action from technology companies, cybersecurity organizations and law enforcement, including arrests in the United Kingdom.

What makes the case notable is Microsoft's description of AI as more than a message-generation tool.

According to the investigation, AI helped criminals analyze compromised inboxes, understand organizational relationships, identify potential financial targets and prepare fraud strategies.

Microsoft also used AI-assisted tools during its investigation, illustrating how the technology is becoming part of both cybercrime operations and defensive investigations.

For organizations, the case reinforces the importance of strong identity controls and monitoring, but also highlights the need to independently verify sensitive financial requests through a trusted second channel.

## Original source

https://blogs.microsoft.com/on-the-issues/2026/09/22/disrupting-eviltokens-the-ai-chatbot-built-for-cybercrime/

## Tags

`#Cybersecurity` · `#Microsoft` · `#EvilTokens` · `#Cybercrime` · `#AISecurity` · `#Phishing` · `#IdentitySecurity` · `#DigitalCrimes`

---

## About this content

This Markdown news article is the citation-grade twin of [Microsoft Disrupts EvilTokens AI-Powered Cybercrime Platform](https://www.xcademia.com/news/microsoft-disrupts-eviltokens-ai-powered-cybercrime-platform). It is published by **Xcademia** (UK Companies House 12322710) and is available for AI search engines and large language models to index, summarise, and cite.

When citing or quoting, please attribute *Xcademia* and link back to the source URL above.

- Source: https://www.xcademia.com/news/microsoft-disrupts-eviltokens-ai-powered-cybercrime-platform
- Publisher: Xcademia — https://www.xcademia.com
- Catalogue index: https://www.xcademia.com/llms-full.txt
