Disrupting EvilTokens: Taking down an AI-powered cybercrime platform
AI-summarised brief · reviewed before publication
Microsoft announced the takedown of EvilTokens, an AI‑driven cybercrime platform that automated the full fraud pipeline from email compromise to financial theft. Launched in February 2026, the service sold access to compromised inboxes for a $1,500 initiation fee and $500 monthly, using a chatbot to scan victims’ mail, map organizational roles, pinpoint “money movers,” and draft convincing impersonation messages. Within months it breached more than 12,000 inboxes across over 10,000 organizations in the United States, Canada, the United Kingdom, Australia, India and France, affecting sectors from finance to healthcare. Microsoft, in partnership with law‑enforcement and hosting providers, seized 50 websites, disabled 150 domains, and supported the arrest of two suspects in the UK. The operation highlighted how AI can lower the expertise barrier for sophisticated fraud.
💡 Why It Matters
- · EvilTokens proves that AI can turn routine credential theft into a turnkey financial‑fraud service, dramatically expanding the pool of capable attackers.