TLDRocket
Sign in

Microsoft disrupts AI-assisted platform that compromised 12,000 accounts

Ars Technica Dan Goodin

Microsoft says it helped shut down EvilTokens, a scam platform that hit 12,000 accounts. It used an AI chatbot to speed up account theft and fraud.

Based on reporting by Ars Technica, Dan Goodin — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Microsoft said on Tuesday that it worked with others in the industry to disrupt EvilTokens, a subscription scam platform that used an AI chatbot to help compromise Microsoft accounts. Over a few months, the service was linked to 12,000 accounts getting hit.

EvilTokens showed up on a Telegram channel in February and sold access like a service package. It charged $1,500 upfront, then $500 every month after that. In return, customers got a tool that stripped away a lot of the grunt work involved in taking over email accounts at scale.

That mattered because the platform was not just about getting in. Once inside, it could help analyze inboxes, pick out targets with the best payoff, and draft follow-up emails that looked believable enough to push employees into moving money to attacker-controlled accounts. The idea was speed. Minutes, not days.

Microsoft said the chatbot at the center of the system could scan a victim’s inbox and surface trusted relationships, payment approvals, and other sensitive duties that made fraud more likely to work. It could also suggest fraud tactics, including messages that impersonated trusted contacts. That’s the ugly part: the scam wasn’t merely automated, it was tuned to sound human.

My take — AI-written commentary, not fact-checked reporting

This is where the AI hype gets a very ugly little side hustle. A tool that helps criminals sound like trusted coworkers isn’t a clever demo; it’s a reminder that “assistive” software is neutral only until someone points it at payroll. The industry keeps acting surprised that friction reduction works for fraud too.

Read more about this at: Ars Technica

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.