Microsoft has led an industry-wide disruption of a subscription-based scam platform known as EvilTokens, which compromised 12,000 Microsoft accounts over a few months. The platform, introduced on Telegram in February, charged an initial $1,500 fee with a recurring $500 monthly charge, offering a single service for streamlining the compromise of email accounts.
EvilTokens provided a sophisticated toolset, allowing customers to analyze inboxes, select targets, and draft convincing follow-up emails. The AI-style chatbot at the core of the service could analyze a victim’s inbox, identify trusted relationships, and even recommend fraud strategies.
The platform's impact was significant, with 10,000 organizations around the world affected, particularly concentrated in the US, followed by Canada, the UK, Australia, India, and France. Victims included a diverse range of industries, including wholesale distribution, construction, financial services, real estate, higher education, and healthcare.
Microsoft and its partners seized 50 websites and 150 domains used to operate EvilTokens, and arrested two men in the UK on suspicion of crimes related to the platform. The account compromises were achieved through a legitimate OAuth process known as device code authentication, highlighting the potential vulnerabilities of such systems.







