Microsoft disrupts AI-assisted platform after 12,000 accounts compromised
microsoft
| Source: Ars Technica | Original article
Microsoft led an industry-wide takedown of the AI‑driven EvilTokens platform that enabled the compromise of 12,000 accounts.
Microsoft announced Tuesday that it had coordinated an industry‑wide takedown of a subscription‑based fraud platform known as EvilTokens. The service, sold on Telegram for a $1,500 setup fee plus $500 a month, leveraged an AI‑driven chatbot to automate account‑takeover attacks that compromised roughly 12,000 Microsoft accounts across 10,000 organizations, primarily in the United States, over a few‑month period.
EvilTokens combined AI‑powered mailbox analysis with abuse of the OAuth device‑code authentication flow, allowing attackers to harvest credentials at scale without direct user interaction. By packaging the operation as a “plug‑and‑play” service, the platform lowered the technical barrier for cybercriminals, turning sophisticated account‑hijacking into a commodity.
The disruption matters because it exposes a new model for automated fraud that blends generative AI with existing authentication weaknesses. As more services adopt AI assistants and OAuth‑based sign‑ins, the attack surface widens, raising concerns for enterprises that rely on Microsoft 365 and Azure AD for daily operations. The breach also underscores the need for tighter controls around device‑code grants and for monitoring AI‑generated traffic that may mask malicious intent.
Going forward, Microsoft is expected to roll out mitigations for the OAuth device‑code flow and to share threat‑intel with partners to curb similar services. Observers will watch for updates on any legal actions against the platform’s operators, as well as for broader industry moves to harden AI‑enabled authentication pathways against abuse.
Sources
Back to AIPULSEN