Microsoft Says It Disrupted AI-Assisted Email Fraud Platform EvilTokens

Microsoft says it and its partners have disrupted EvilTokens, a service that combined access to compromised email accounts with AI tools designed to identify promising targets for financial fraud. In a September 22 disclosure, the company said a U.S. court-authorized operation took control of 50 sites used by the service and disabled more than 150 related domains. Those figures and the description of the platform are Microsoft’s investigative findings, not an independent count established by NOWLIVO.

Build your technology Talent Passport with MAANIH Talent

The distinguishing risk is what happens after an inbox is opened. According to Microsoft, the service could summarize messages, map colleagues’ roles and payment permissions, and identify existing vendor relationships. A forged request that fits a real conversation may be harder to spot than a generic phishing email. AI can accelerate that review, but it is the unauthorized account access and subsequent impersonation that create the fraud opportunity.

Microsoft says the initial access often involved a device-code trick: a person entered an authentication code on a legitimate Microsoft sign-in page, unwittingly granting an attacker a session. This helps explain why a password change alone may not close an incident. Active sessions and tokens can need revocation, and organizations must review what the account accessed or sent. The company says it notified affected customers and assisted with remediation.

Microsoft linked the platform to more than 12,000 compromised inboxes at over 10,000 organizations after its February launch. The company described civil litigation and cooperation with industry partners and UK police. It said two men were arrested on suspicion of offenses connected to the alleged operation and later released on police bail while inquiries continue. An arrest is not a finding of guilt.

The disruption may remove specific infrastructure, but it does not establish that every compromised account is secure or that similar services have ceased operating. For readers and businesses, the useful distinction is between verifying a sender’s account and verifying a request: a message from a genuine but compromised mailbox can still be fraudulent. Changes to bank details or unusual payment instructions warrant a check through a previously trusted, separate channel.