Microsoft disrupts EvilTokens, an AI-assisted service linked to 12,000 compromised inboxes
EvilTokens(ee-vil tokens)
A paid service that helped criminals access email and prepare fraud.
compromised inbox(kom-pruh-mized in-box)
An email inbox accessed without the owner’s permission.
business email compromise(business email compromise)
Fraud that uses a stolen work email account.
Microsoft says it disrupted EvilTokens, a paid service that used AI to help criminals take over email accounts and prepare fraud. The company linked the operation to more than 12,000 compromised inboxes across more than 10,000 organizations worldwide. These figures come from the investigation. They do not show that every organization lost money or that every suspected operator was convicted. This summary draws on Microsoft’s announcement and Ars Technica’s report.
What happened
EvilTokens appeared on Telegram in February 2026. It reportedly charged $1,500 to start and $500 each month. The service combined account access, mailbox analysis, target selection, and fraud preparation. Its AI chatbot could inspect a compromised inbox. It could identify trusted relationships, payment authority, and likely opportunities. It could also suggest stories and draft messages that impersonated trusted contacts.
Microsoft says victims were led to enter a code on a normal Microsoft sign-in page. That could give criminals account access without revealing a password. The important point is simple: EvilTokens joined several steps into one paid package.
Background: more than better-written messages
Email fraud often depends on understanding how an organization works. Someone must find who approves payments, who reports to whom, and which suppliers or customers matter. EvilTokens packaged that research into a service. Its AI could sort messages and highlight useful relationships.
Human users still chose what to do. The AI did not magically complete every attack. Instead, it shortened the reading and planning work. That made a complex fraud process easier to buy and repeat.
Why it matters
AI did more here than write polished phishing messages. It helped turn stolen email access into a map of an organization. That pattern is commonly called business email compromise: using a stolen work account to pursue fraud. When software can find payment roles and trusted contacts quickly, less experienced criminals may attempt scams at greater scale.
A compromised inbox can contain more than private messages. It may reveal payment schedules, internal trust, and pending business decisions. That is why the risk continues after an account is first accessed.
What is confirmed
Microsoft says its Digital Crimes Unit worked with Health-ISAC and other partners. With authorization from the U.S. District Court for the Eastern District of Virginia, the group seized 50 websites and disabled more than 150 additional domains. The Metropolitan Police Service in the United Kingdom arrested two men on suspicion of offenses connected with the alleged operation. Microsoft says both were released on bail while the investigation continues. An arrest is not a conviction.
The affected sectors included wholesale distribution, construction, financial services, real estate, higher education, and healthcare. The highest concentrations were reported in the United States, Canada, the United Kingdom, Australia, India, and France.
What remains unknown
Public information does not yet show total financial losses, a complete victim list, or whether every affected account has been fully secured. It is also unclear how many people operated the service, whether copies will return under new names, and what legal outcomes the arrested suspects will face. Disrupting EvilTokens matters, but it does not prove that the wider email-fraud market has disappeared.
What to watch next
Organizations should independently verify requests to change payment details, redirect funds, or approve unusual transactions. A second trusted channel can catch a fake request even when an email account looks real. Companies will also watch for new services that copy EvilTokens.
The broader lesson is about coordination. Courts, cloud providers, security firms, AI companies, financial services, and police may all be needed to dismantle one service. AI is helping both attackers and defenders move faster, so response speed will matter as much as model capability.
Microsoft stops a service that used AI to speed up email fraud
📰 Full story: Microsoft disrupts EvilTokens, an AI-assisted service linked to 12,000 compromised inboxes
The service helped criminals study stolen inboxes and choose targets.
EvilTokens(ee-vil tokens)
A paid service for stealing email access and planning fraud.
inbox(in-box)
The place where new email arrives.
AI chatbot(A-I chat-bot)
A computer helper that can read messages and suggest actions.
💡 The gist
- Microsoft, a software company, stopped EvilTokens, a paid crime service.
- It used an AI chatbot to study email and plan fraud.
- More than 12,000 inboxes were linked to the service.
EvilTokens began in February 2026. People sold it through Telegram. Customers paid $1,500 to start. They then paid $500 each month.
An inbox is the place where new email arrives. After criminals entered an account, the service helped study messages. Its AI chatbot searched for trusted coworkers. It also found people who could approve payments. Then it suggested targets and wrote messages that looked like trusted contacts.
Microsoft says victims were led through a normal Microsoft sign-in page. They entered a code without understanding the result. That could give criminals access to email. They did not always need the victim’s password.
The AI did not make every choice alone. Human users still selected targets. The AI made the reading and planning faster. This matters because email can show who handles money. It can also show who trusts whom at work. A stolen inbox can become a guide for fraud.
Microsoft worked with partners and received court permission. The group seized 50 websites. It also disabled more than 150 other domains. UK police arrested two men on suspicion of involvement. They were released on bail. An arrest is not a conviction.
The full money loss is still unknown. The complete victim list is also unknown. New copies of the service could appear later. Companies should check payment changes through another trusted channel. They should keep watching important accounts.
Sources: Microsoft’s announcement and Ars Technica’s report.
An AI helper was used for bad email tricks
📰 Full story: Microsoft disrupts EvilTokens, an AI-assisted service linked to 12,000 compromised inboxes
Microsoft stopped a service that used the helper.
EvilTokens(ee-vil tokens)
A bad online service that used work email.
AI helper(A-I helper)
A computer helper that reads and sorts information.
mailbox(mail-box)
A place where email is kept.
Microsoft, a computer company, stopped EvilTokens, a bad online service.
EvilTokens used an AI helper. The helper read stolen work email. It helped bad people choose targets. It also helped write tricking messages.
More than 12,000 mailboxes were linked to the service. Those mailboxes came from more than 10,000 organizations. This does not mean everyone lost money.
Microsoft and partners stopped 50 websites. They also stopped more than 150 other web addresses. British police arrested two men while investigating. An arrest is not a final court decision.
A stolen mailbox can show who handles money. Important payment changes should be checked another way.
Source: Microsoft’s announcement.