Microsoft Seizes 200 EvilTokens Domains After AI Scam Hit 12,000 Accounts
Updated
Updated · Ars Technica · Sep 22
Microsoft Seizes 200 EvilTokens Domains After AI Scam Hit 12,000 Accounts
3 articles · Updated · Ars Technica · Sep 22
Summary
Microsoft said it dismantled EvilTokens, a subscription scam platform that used an AI chatbot to help criminals compromise 12,000 accounts across 10,000 organizations in a few months.
Using legal action and industry partners, Microsoft seized 50 websites and 150 related domains, while UK police arrested two men suspected of links to the operation.
The service, launched on Telegram in February, charged $1,500 upfront and $500 a month to automate inbox analysis, target selection and realistic payment-fraud emails.
Device code authentication—a legitimate OAuth flow for TVs and other limited-input devices—was the main entry point used to gain account access.
The highest concentration of victims was in the US, followed by Canada, the UK, Australia, India and France, spanning sectors from finance and real estate to healthcare and higher education.