Microsoft took down an AI service linked to 12,000 hacked emails
Microsoft disrupted EvilTokens, an AI-enabled cybercrime platform linked to 12,000+ compromised inboxes across 10,000 organisations, including victims in India.
Microsoft has disrupted EvilTokens, a subscription-based cybercrime platform that allegedly used an AI-style chatbot to help attackers compromise email accounts and prepare financial fraud.
According to Microsoft, the service was linked to more than 12,000 compromised inboxes across over 10,000 organisations worldwide within months of appearing in February 2026. What makes the case notable is how much of the attack process EvilTokens attempted to automate.
Microsoft said its AI tools could analyse a victim's inbox, identify trusted relationships, find people involved in payment approvals and suggest potential impersonation targets.
From $1,500 to a ready-made attack
EvilTokens was allegedly sold through Telegram for $1,500 upfront, followed by a $500 monthly subscription. Microsoft said the platform brought several stages of an attack into one service, including account compromise, mailbox analysis, target selection and fraud preparation.
One of the methods involved device code authentication, a legitimate Microsoft sign-in process designed for devices without conventional login screens. Victims were reportedly tricked into entering a code on Microsoft's official login page.
Rather than handing over a password, they unknowingly authorised access to their email account. Once inside, attackers could use the platform to scan messages for invoices, payment discussions, vendors, employee roles and approval chains.
That information could then be used to create business email compromise attacks, where criminals impersonate trusted contacts to redirect payments or authorise fraudulent transfers.
India was among the affected countries
Microsoft said victim activity was concentrated in the US, Canada, UK, Australia, India and France.
The affected organisations included businesses in wholesale distribution, construction, financial services, real estate, higher education and healthcare.
Microsoft's Digital Crimes Unit worked with partners to seize 50 websites used to operate the service and disable more than 150 additional domains linked to its infrastructure. The operation involved organisations including Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation and TRM Labs.
In the UK, the Metropolitan Police Service's cybercrime team arrested two men, aged 32 and 38, on September 11 in connection with the alleged operation. Microsoft said both were released on police bail while the investigation continues.
AI makes a compromised inbox more valuable
The bigger concern is what happens after an attacker gets into an account. Previously, criminals had to manually work through potentially thousands of emails to understand who handles payments, which vendors an organisation uses and how approval processes work.
AI can speed up that analysis considerably. For businesses, that makes account security more than a password problem. Organisations should revoke stolen tokens and active sessions when an account is compromised, while requests involving payment changes, fund transfers or unusual approvals should be verified through a separate trusted channel.
Microsoft said the EvilTokens operation was the Digital Crimes Unit's first action against an end-to-end AI-enabled cybercrime service.
The infrastructure may have been disrupted, but the model it exposed is harder to ignore: AI can reduce the amount of expertise and manual work needed to turn a compromised inbox into a targeted financial scam.


