Microsoft Disrupts AI Platform That Compromised 12,000 Accounts
▼ Summary
– Microsoft disrupted the EvilTokens scam platform, which used an AI chatbot to compromise over 12,000 Microsoft accounts across multiple countries.
– The subscription-based service charged users fees to streamline email account compromises and generate realistic phishing emails for financial fraud.
– Victims included organizations in sectors such as finance, healthcare, and construction, with the highest concentration of breaches occurring in the US.
– Attackers utilized a legitimate OAuth mechanism called device code authentication, typically intended for TVs, to gain unauthorized access to user accounts.
– Following the disruption, Microsoft seized numerous domains and websites while UK police arrested two men connected to the criminal operation.
The Rise of the EvilTokens AI Scam
Microsoft has successfully dismantled a sophisticated, subscription-based cybercrime infrastructure known as EvilTokens, which utilized artificial intelligence to breach the accounts of 12,000 users across thousands of organizations. The platform, which launched via a Telegram channel in February, operated on a lucrative business model that charged an upfront fee of $1,500 followed by monthly recurring payments of $500. This service streamlined the complex process of large-scale account compromise, offering criminals an automated way to identify high-value targets and execute fraud with unprecedented efficiency.
The core of the EvilTokens ecosystem was an AI-powered chatbot designed to analyze victim email inboxes for sensitive data. By mapping out trusted relationships, payment authorizations, and internal responsibilities, the tool allowed attackers to pinpoint where fraud would be most effective. It went beyond simple reconnaissance; the system could generate realistic phishing narratives and draft follow-up messages impersonating colleagues or executives. These tactics were engineered to trick employees into transferring funds to attacker-controlled accounts, turning standard corporate communications into weapons of financial theft.
Targeted Industries and Global Reach
The scope of the breach was significant, affecting approximately 10,000 distinct organizations worldwide. While the United States suffered the highest concentration of compromised accounts, other heavily impacted nations included Canada, the United Kingdom, Australia, India, and France. The victims spanned a diverse array of critical sectors, including wholesale distribution, construction, financial services, real estate, higher education, and healthcare. These industries were targeted because they often handle substantial financial transactions and possess internal structures that are vulnerable to social engineering attacks.
Security firm SpyCloud provided additional insights into the victim landscape, highlighting how the attackers leveraged the AI’s ability to understand context within corporate environments. By analyzing past correspondence, the platform helped criminals craft highly convincing ruses that bypassed traditional security awareness training. The result was a rapid escalation in successful intrusions, with the platform enabling bad actors to move from initial access to financial exploitation in a matter of minutes rather than days.
Law Enforcement Action and Technical Vulnerabilities
In response to the threat, Microsoft collaborated with legal authorities and industry partners to seize control of the operation. The effort resulted in the takedown of 50 websites and 150 associated domains used to facilitate EvilTokens. Furthermore, the UK’s Metropolitan Police Service arrested two men in connection with the crime platform, marking a significant step in holding the operators accountable.
The technical mechanism behind these compromises relied on OAuth device code authentication. This legitimate protocol is typically intended for TVs and other devices lacking full keyboard interfaces, where a user enters a code displayed on one screen into a browser on another to authorize access. Cybercriminals exploited this feature by initiating the authentication process on behalf of the victim. Once the victim unknowingly entered the code on their personal device, the attacker gained immediate access to the email account without needing to steal passwords or trigger multi-factor authentication alerts. This abuse of a trusted authentication method allowed the EvilTokens platform to operate under the radar until its underlying infrastructure was disrupted.
(Source: Ars Technica)




