A stolen work inbox can tell a criminal a lot about a company. It can show who approves payments, which suppliers the company works with, and how employees communicate.
Microsoft says EvilTokens used AI to turn that information into a fraud plan. Its chatbot could search compromised inboxes, identify people involved in payments, and suggest whom an attacker should impersonate.
Microsoft announced the disruption on September 22. Investigators linked the service, which appeared in February 2026, to more than 12,000 compromised inboxes across over 10,000 organizations worldwide.
The case shows how AI can speed up what happens after an account is hacked. The main change is not better phishing emails. It is faster analysis of stolen business information.
Victims signed in on a real Microsoft page
EvilTokens used device-code authentication, a legitimate Microsoft sign-in method for devices that cannot easily show a standard login screen. A user receives a short code and enters it in a browser to approve access.
Attackers abused that process by tricking victims into entering codes connected to attacker-controlled sessions. Microsoft’s investigation found that victims still completed the sign-in on its legitimate website, but the code they entered was linked to an attacker-controlled session.
The problem was the session being approved. Once the victim entered the code, the attacker received an authentication token that could provide access to the account. The criminal did not need to steal the password itself.
This made the attack harder to recognize because the Microsoft page was legitimate. Microsoft also found malicious inbox rules that could hide messages after the account was compromised, giving attackers more time to operate unnoticed.
The AI could search for payment opportunities
Once attackers gained access to an inbox, EvilTokens could help them decide what to do next.
Microsoft says preset prompts could search for wire transfers or vendor invoices. Other prompts identified people involved in moving money and suggested people the attacker could impersonate.
For business email compromise, this information can make fraud more convincing. An attacker who knows which employee approves payments and which vendor is expecting money can create a request that matches a real business relationship.
The Neuron has previously covered how AI can reduce the effort required to run scams. EvilTokens shows how the same technology can help criminals analyze information after they already have access to an account.
A criminal would normally have to read through messages and work out who handles payments. EvilTokens could reportedly do some of that research through chatbot prompts. Microsoft did not publish data on how much time the system saved, so the exact speed advantage remains unknown.
EvilTokens bundled multiple cybercrime tasks into one service
EvilTokens charged a $1,500 initiation fee and $500 per month. It was sold through Telegram and included customer support plus management dashboards.
Customers were therefore paying for more than a phishing tool. The service combined account access with mailbox analysis and fraud preparation in one product.
Microsoft also found evidence that AI helped build EvilTokens itself. Investigators said large portions of the platform were “vibe coded,” meaning its developers used AI tools to help write the software. EvilTokens also used capabilities from several AI models.
AI played two roles in the operation, helping developers build the platform and helping customers analyze stolen inboxes. Microsoft did not estimate how much development work the AI tools replaced.
The business generated substantial revenue. CyberScoop reported that Coinbase traced about $1.1 million in payments from EvilTokens customers through June 2026.
Microsoft also linked at least 13 FBI Internet Crime Complaint Center complaints to EvilTokens activity, representing about $1.7 million in reported losses. The company said it could not estimate the total amount of fraud connected to the service.
Companies may have less time after an account is compromised
Microsoft and its partners seized 50 websites and disabled more than 150 additional domains connected to EvilTokens. UK police arrested two men, ages 32 and 38, on suspicion of administering the service. Both were later released on bail while the investigation continued, according to The Register.
Microsoft called the operation its Digital Crimes Unit’s 40th court-authorized disruption and its first against an end-to-end AI-enabled cybercrime service.
Disrupting EvilTokens does not eliminate the risk. Criminals can combine stolen mailbox access with AI tools that search conversations for payment information and trusted relationships.
Microsoft says companies should assume that attackers may understand a compromised inbox within minutes. It recommends confirming payment changes through a separate trusted channel.
For security teams, this shortens the time between account takeover and attempted fraud. Restoring access may only solve part of the problem if the attacker has already learned who controls payments and which business relationships can be copied.