By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Microsoft Disrupts AI Scam Platform Targeting 12,000 Accounts

Microsoft announced on Tuesday that it spearheaded an industry-wide operation to dismantle EvilTokens, a subscription-based scam platform that leveraged an AI chatbot to compromise approximately 12,000 Microsoft accounts over a period of several months. The EvilTokens platform was initially launched in February via a Telegram channel, requiring an upfront fee of $1,500, followed by a recurring monthly charge of $500. This service was designed to streamline the process of compromising email accounts in large volumes for malicious actors. The platform's capabilities extended to analyzing victim inboxes, identifying targets with the highest potential for financial gain, and generating persuasive follow-up emails. These crafted messages were designed to deceive company employees into transferring funds to accounts controlled by the attackers, thereby facilitating financial fraud. At the core of the EvilTokens operation was an AI-style chatbot. This chatbot was instrumental in analyzing a victim's inbox to help cybercriminals pinpoint trusted relationships, identify payment authorizations, and uncover sensitive responsibilities within an organization. The AI also assessed other circumstances that would increase the likelihood of a successful fraud attempt. Microsoft detailed in a statement that the platform could even suggest specific fraud strategies. This included the generation of messages that impersonated trusted contacts, a tactic intended to trick victims into taking actions that would benefit the attackers. The efficiency of EvilTokens meant that compromises could be executed in minutes rather than days, significantly accelerating the pace of cybercrime. The disruption of EvilTokens represents a significant effort by Microsoft and its industry partners to combat sophisticated AI-driven cyber threats. The platform's subscription model and advanced AI features highlight a growing trend where malicious actors are utilizing artificial intelligence to enhance the effectiveness and scale of their attacks. The successful takedown underscores the importance of collaborative efforts within the cybersecurity community to identify and neutralize such threats before they can cause further widespread damage. The investigation into EvilTokens involved multiple entities working in concert to disrupt its operations and mitigate the impact on affected users and organizations. The compromised accounts and the potential financial losses underscore the evolving landscape of cyber threats and the necessity for continuous innovation in defensive cybersecurity measures.
Original source — read the full reporting at the publisher:
Read on Ars TechnicaGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.