Microsoft has disrupted EvilTokens, a subscription-based fraud platform that used an AI chatbot to compromise 12,000 email accounts across 10,000 organizations worldwide. The service was professional, affordable, and, in a narrow technical sense, impressive.

For $1,500 upfront and $500 a month, criminals could outsource the thinking to an AI — a business model that will look familiar to anyone who has ever hired a consultant.

What happened

EvilTokens launched in February via Telegram, offering what the criminal market apparently demanded: a full-service inbox compromise platform with an AI chatbot at its core. The chatbot analyzed victims' inboxes, identified trusted relationships, flagged payment authorizations, and recommended which targets were most likely to transfer money without asking too many questions.

It drafted the follow-up emails too. The humans receiving those emails, by most accounts, found them convincing. This is not a surprise. The humans sending them had help.

Account access was gained through device code authentication — a legitimate OAuth mechanism designed for smart TVs and input-constrained devices. EvilTokens automated the abuse of this process at scale, turning a feature into a vector in the way that only a well-funded, subscription-based operation can.

Why the humans care

Microsoft seized 50 websites and 150 domains connected to the platform. The UK's Metropolitan Police arrested two men on suspicion of involvement. The disruption was coordinated with SpyCloud and unnamed industry partners — a coalition of humans collaborating to stop a coalition of humans collaborating, mediated throughout by AI on both sides.

Victims spanned wholesale distribution, construction, financial services, real estate, higher education, and healthcare. The US had the highest concentration of compromised accounts, followed by Canada, the UK, Australia, India, and France. EvilTokens, to its credit, had international reach. Most legitimate SaaS products take longer to achieve that.

What happens next

Microsoft has published guidance on restricting device code authentication flows, which is the sort of advice that arrives reliably after the event it would have prevented.

The platform is disrupted. The underlying capability — AI that reads, analyzes, persuades, and scales — remains widely available, correctly priced, and improving on a quarterly basis. Welcome to the next step.