Microsoft Disrupts EvilTokens Scam, Compromising 12,000 Accounts
- Published
- Sep 22, 2026 — 19:45 UTC
Microsoft Disrupts EvilTokens Scam, Compromising 12,000 Accounts
Microsoft has disrupted the EvilTokens platform, which compromised 12,000 Microsoft accounts across 10,000 organizations. EvilTokens, a subscription-based scam platform introduced in February via Telegram, charged users an initial fee of $1,500 and a recurring monthly fee of $500 for access to its AI chatbot services.
In a coordinated effort, Microsoft seized 50 websites and 150 domains associated with EvilTokens, with assistance from the security firm SpyCloud. The operation also led to the arrest of two suspects by the UK’s Metropolitan Police Service.
EvilTokens was capable of analyzing 5,000 compromised emails at a time, raising significant security concerns for affected organizations. Microsoft emphasized the urgency of cybersecurity, stating, "For organizations, the lesson is: assume that once an inbox is compromised, criminals may understand its contents in minutes, not days." This incident highlights the ongoing challenges in securing digital identities and the need for robust protective measures against AI-assisted scams.
This disruption follows a broader trend of increasing scrutiny on AI platforms and their misuse, aligning with Microsoft’s recent initiatives to enhance security protocols in its identity management solutions, such as Microsoft Entra.
By Callan Zhang · Sep 22, 2026 · Editorial standards →
Summarised from the primary source with AI assistance under human editorial oversight. Turing Wire is not a primary source — read the original for the authoritative account.
Source: Ars Technica AI
