Microsoft disrupts AI-assisted platform that compromised 12,000 accounts
Ars Technica Dan Goodin
Microsoft says it helped shut down EvilTokens, a scam platform that hit 12,000 accounts. It used an AI chatbot to speed up account theft and fraud.
Based on reporting by Ars Technica, Dan Goodin — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
Microsoft said on Tuesday that it worked with others in the industry to disrupt EvilTokens, a subscription scam platform that used an AI chatbot to help compromise Microsoft accounts. Over a few months, the service was linked to 12,000 accounts getting hit.
EvilTokens showed up on a Telegram channel in February and sold access like a service package. It charged $1,500 upfront, then $500 every month after that. In return, customers got a tool that stripped away a lot of the grunt work involved in taking over email accounts at scale.
That mattered because the platform was not just about getting in. Once inside, it could help analyze inboxes, pick out targets with the best payoff, and draft follow-up emails that looked believable enough to push employees into moving money to attacker-controlled accounts. The idea was speed. Minutes, not days.
Microsoft said the chatbot at the center of the system could scan a victim’s inbox and surface trusted relationships, payment approvals, and other sensitive duties that made fraud more likely to work. It could also suggest fraud tactics, including messages that impersonated trusted contacts. That’s the ugly part: the scam wasn’t merely automated, it was tuned to sound human.
My take — AI-written commentary, not fact-checked reporting
This is where the AI hype gets a very ugly little side hustle. A tool that helps criminals sound like trusted coworkers isn’t a clever demo; it’s a reminder that “assistive” software is neutral only until someone points it at payroll. The industry keeps acting surprised that friction reduction works for fraud too.
Read more about this at: Ars Technica