A service that combined stolen access with AI

Microsoft says it has disrupted EvilTokens, a cybercrime service that paired compromised email accounts with an AI-style chatbot for fraud planning. The Microsoft announcement, published on 22 September, describes a service that could search a victim’s inbox, map trusted relationships and suggest convincing impersonation messages. This is not a new Microsoft product announcement; it is a significant enforcement and threat-intelligence update about the misuse of AI.

The Digital Crimes Unit says EvilTokens had been linked to more than 12,000 compromised inboxes at over 10,000 organisations within months of its February launch. Microsoft observed victim activity in several countries, including Australia. Those are the company’s observed figures, not a complete count of everyone who may have been affected. They nevertheless indicate the scale at which a ready-made service can put sophisticated fraud preparation within reach of less experienced operators.

With partners, Microsoft seized 50 websites used to operate the service and disabled more than 150 supporting domains. The Metropolitan Police Service in the United Kingdom arrested two men on suspicion of connected offences, according to Microsoft. The company calls this its first court-authorised disruption of an end-to-end AI-enabled cybercrime service.

How the attack chain worked

The account-access technique described by Microsoft tricked a person into entering an authentication code on a legitimate sign-in page. The victim was not necessarily asked to disclose a password. Instead, the action completed a normal-looking authentication flow that gave the attacker a usable session. This is why a password reset alone may not remove access: active sessions and tokens may also need to be revoked.

Once an attacker had mailbox access, EvilTokens could summarise and translate messages, identify payment conversations and map who appeared to authorise transfers. Preset prompts reportedly looked for vendor invoices, wire-transfer discussions and staff with financial authority. The AI component reduced the manual work of learning how a business operates, allowing an attacker to tailor a message to a real relationship rather than send a generic scam.

Microsoft says the service was sold through Telegram for a US$1,500 initiation fee and a US$500 recurring subscription. This pricing is part of the threat story: it packaged account compromise, intelligence gathering and fraud preparation into a commercial offering. It does not mean every customer used every feature or that all linked inboxes led to financial loss.

What the disruption does and does not solve

Taking down domains can interrupt a service and create evidence for investigators. It does not automatically repair compromised accounts, reverse fraudulent payments or prevent a successor from copying the method. Organisations that suspect exposure should examine sign-in logs and device-code activity, revoke active sessions where appropriate and review mailbox forwarding rules as well as credentials.

Payment controls matter because the attacker’s goal was often to exploit a credible conversation. A request to change bank details or accelerate a transfer should be confirmed through an established contact channel, not by replying to the thread that may already be compromised. Finance staff need a process that survives a convincing message from an apparently familiar address.

Microsoft Threat Intelligence has published additional technical guidance on device-code attacks. Security teams should pair that advice with their own identity provider settings and incident-response procedures. The incident is a reminder that multifactor authentication can be undermined by social engineering if the user is induced to approve the attacker’s session.

The broader lesson for AI-enabled fraud

AI changed the speed and specificity of the fraud workflow, according to Microsoft. It could turn an inbox into a map of relationships and payment habits, then suggest who to impersonate. The defender’s response therefore needs to cover both identity security and business process. Blocking a domain helps only part of the problem if an attacker still holds valid access or a payment team trusts email alone.

For Australian organisations, a practical tabletop exercise would begin with a compromised finance mailbox and a plausible invoice amendment. Ask how quickly the team can identify the session, revoke access, detect forwarding rules and stop a payment. Include communications to suppliers and staff, because a technical fix does not undo messages already sent from an account.

The disruption is material because it targets a service designed around AI-assisted financial crime rather than a single malicious campaign. Its lasting value will depend on whether organisations use the evidence to harden sign-ins, token revocation and payment verification. Microsoft’s account supplies a concrete example of the threat; it does not establish that any particular organisation is compromised.

Staff education should make this mechanism tangible without blaming a victim for a convincing prompt. Explain that a legitimate-looking sign-in page can still complete an attacker-initiated flow, and provide a simple route to report an unexpected code request. Quick reporting can give responders time to invalidate sessions before mailbox analysis becomes a fraud attempt.