Safety2 min read

Microsoft Shuts Down AI Scam Tool That Hit 12,000 Accounts

By , Senior AI ConsultantPublished

Microsoft and police dismantled EvilTokens, a paid subscription hacking service whose built-in AI chatbot read stolen inboxes to find the best person to impersonate and the best moment to request a wire transfer.

Microsoft, a healthcare security group called Health-ISAC, and police in the UK have taken down a criminal service called EvilTokens. It compromised more than 12,000 company email inboxes across over 10,000 organizations worldwide, in just a few months.

What makes this worth your attention is not the size. It is the business model. EvilTokens was sold on Telegram like a piece of normal software, with a 1,500 dollar sign-up fee and a 500 dollar monthly subscription.

About 1,000 criminals paid for access, and just ten of them were responsible for 60 percent of all the victims, according to research firm SpyCloud. Crime, in other words, is now run like a subscription business with a small group of power users doing most of the damage.

The break-in method is also worth understanding, because it is not what most people picture when they hear "hacking." Instead of stealing a password, EvilTokens tricked employees into approving a sign-in request that looked exactly like a normal Microsoft login screen.

Once approved, the criminal received a working login token, the same kind of digital pass your phone or laptop uses to stay signed in. No password was needed, and the usual security alarms never went off.

The part that should worry any business is what happened after that. EvilTokens included a built-in AI chatbot that read through the stolen mailbox, in more than twenty languages, and worked out who approved payments and which vendor relationships could be exploited. It then drafted a follow-up email pretending to be a trusted contact, timed to look like a normal request for a wire transfer or invoice payment.

This is the shift that matters for any company that moves money by email, which is nearly all of them. Convincing scam emails used to require a skilled person who studied a company for weeks. Now a criminal with no special skill can rent that research and writing ability for 500 dollars a month.

This kind of fraud, known as business email compromise, already costs businesses billions of dollars a year in reported losses to the FBI. That was before AI made the research step nearly free.

Microsoft's Digital Crimes Unit said this was its 40th court-ordered takedown of a cybercrime operation, but the first aimed at what it calls a full AI-powered crime service. Two men, aged 32 and 38, were arrested in London and released on bail while the investigation continues, and Microsoft's legal filing names five more unidentified people it believes helped run the operation.

Taking one service offline will not end this. The pattern of quick, cheap, subscription-based crime tools built around AI is now established, and copies will follow.

The most useful response for any business is not a new piece of security software. It is a simple habit: any request to change a payment, a bank account, or a wire transfer should be confirmed by phone with someone you already know, never by replying to the email itself, no matter how convincing it sounds.


STAY INFORMED

Get AI intelligence like this delivered to your inbox.

Free forever · Unsubscribe anytime


You May Also Find Valuable