Microsoft Disrupts EvilTokens AI Phishing Service Linked to 12,000 Compromised Inboxes

Image: Ars Technica AI
Main Takeaway
Microsoft disrupted EvilTokens, an AI-enabled phishing service tied to more than 12,000 compromised inboxes across over 10,000 organizations worldwide.
Jump to Key PointsSummary
Microsoft targets a commercial attack platform
Microsoft disrupted EvilTokens, a subscription cybercrime service that linked account takeover, artificial intelligence and financial fraud into one commercial operation. The platform was associated with more than 12,000 compromised inboxes across over 10,000 organizations, according to Microsoft and security companies involved in the operation.
The service was promoted through Telegram beginning in February and charged $1,500 upfront, followed by a $500 monthly fee. Microsoft’s Digital Crimes Unit coordinated the action with Health-ISAC, Coinbase, TRM Labs, other industry partners and law enforcement. The operation involved seizing websites and disabling domains used to run the service, according to Microsoft.
How EvilTokens automated account compromise
EvilTokens compressed a complex intrusion process into a service that attackers could rent. Its tools helped criminals obtain access to email accounts, analyze inboxes and impersonate trusted contacts, while an AI-style chatbot organized information for later scams.
The system examined messages for financial details, business relationships and transaction patterns. Attackers then used those findings to create convincing requests for payments, account changes or sensitive information. Coverage from Ars Technica AI and The Hacker News identifies device-code phishing as part of the operation, a technique that can trick victims into authorizing access without handing over a password directly.
That combination gave criminals a path around some conventional defenses. A compromised session or token can let an attacker act as the account holder, while details extracted from legitimate email threads make fraudulent messages harder for recipients to spot. TRM Labs described the service as packaging account takeover, mailbox analysis and fraud tooling into a single offering.
The financial fraud connection
EvilTokens turned stolen inbox access into a fraud engine. Compromised accounts could reveal invoices, payment instructions, vendor contacts and ongoing negotiations, giving criminals the context needed to redirect legitimate transactions or impersonate executives and suppliers.
The affected organizations ranged across sectors including real estate, banking and healthcare, according to Fortune AI and Fortune’s social-media post. Microsoft’s account of the operation also described attack planning that supported financial fraud and scams, while TRM Labs connected the service to business email compromise activity.
The economic damage extends beyond the initial login. Once attackers enter a mailbox, they can monitor conversations, suppress warnings, alter payment details and target additional employees or partners. That makes a single stolen account useful as both a source of intelligence and a launch point for follow-on attacks. The 12,000-inbox figure measures identified compromises, while the number of fraudulent attempts and losses varies across accounts and victims.
Why the takedown matters for defenders
The disruption highlights a shift toward cybercrime services that sell packaged workflows rather than isolated malware. EvilTokens handled several stages of an attack in one subscription, lowering the technical skill required to conduct targeted phishing and business email compromise.
Microsoft’s action also shows how platform operators, financial firms and threat-intelligence companies are combining their visibility. Coinbase contributed to the investigation, and TRM Labs supported cryptocurrency and criminal-infrastructure analysis. Health-ISAC brought sector-specific intelligence from healthcare organizations, according to the participating groups.
Defenders should treat mailbox access as an active incident, not simply a password-reset event. Organizations need to revoke sessions and tokens, inspect device-code authentication, review inbox rules and forwarding settings, search for altered payment instructions, and contact affected business partners. Employees handling invoices or account changes need a second communication channel for verification.
A broader Microsoft cybercrime campaign
EvilTokens is part of a wider series of Microsoft-led actions against commercial cybercrime infrastructure. Separate operations described by Microsoft and industry coverage targeted RedVDS, a subscription service linked to more than $40 million in reported U.S. fraud losses, as well as infrastructure associated with StealC and Amadey malware.
Microsoft also disclosed action against Fox Tempest, a malware-signing service tied to ransomware attacks on hospitals and other critical organizations. These cases share a common structure: specialized services provide infrastructure, access or evasion capabilities to many downstream criminals, allowing a relatively small operator network to support a much larger attack economy.
The pattern gives technology companies a legal and operational target beyond individual phishing emails. Seizing domains, disabling infrastructure and pursuing court action can raise costs for service operators, although replacement services and copied tooling can reappear under new names.
What happens after the disruption
The immediate effect is reduced access to EvilTokens’ sites, domains and operational tools. Microsoft’s action also gives affected organizations a reason to review identity logs, mailbox activity and payment-fraud controls, particularly where device-code authentication or suspicious session activity appears.
The longer contest will center on reuse. Criminal groups can rebuild services, copy interface designs and shift communications to new channels. Security teams therefore need controls that detect abnormal mailbox behavior and token use, not only known EvilTokens domains or signatures.
The case also puts pressure on cloud providers, identity platforms, exchanges and threat-intelligence firms to share indicators quickly. AI did not create the underlying phishing and account-takeover techniques, but EvilTokens used it to organize them at subscription scale. That commercial packaging is the central security lesson from the takedown.
Key Points
Microsoft disrupted EvilTokens, an AI phishing service tied to 12,000 compromised inboxes across 10,000 organizations.
EvilTokens charged $1,500 upfront and $500 monthly for account takeover and fraud automation tools.
The platform used an AI chatbot to analyze inboxes and support impersonation and financial scams.
Device-code phishing helped attackers obtain access without relying solely on stolen passwords.
Microsoft coordinated the takedown with Health-ISAC, Coinbase, TRM Labs and law enforcement.
Questions Answered
EvilTokens was a subscription cybercrime platform that combined phishing, account takeover, AI-assisted inbox analysis and fraud tools. Microsoft disrupted its websites and domains after linking the service to more than 12,000 compromised inboxes across over 10,000 organizations.
EvilTokens used an AI-style chatbot to analyze compromised email accounts and identify useful information for impersonation and financial fraud. The system helped attackers organize mailbox intelligence and plan targeted scams.
EvilTokens used device-code phishing and related token-based techniques to obtain authenticated access to accounts. This allowed attackers to operate through authorized sessions even when victims had multifactor authentication enabled.
EvilTokens affected organizations in sectors including real estate, banking and healthcare. Microsoft-linked investigations identified more than 12,000 compromised inboxes across over 10,000 organizations.
Organizations should revoke suspicious sessions and tokens, investigate device-code authentication, inspect mailbox forwarding rules and verify payment changes through a separate channel. Security teams should also review impersonation attempts and unusual inbox activity.
Source Reliability
42% of sources are trusted · Avg reliability: 68
Go deeper with Organic Intel
Simple AI systems for your life, work, and business. Each one includes copyable prompts, guides, and downloadable resources.
Explore Systems