Microsoft disrupts EvilTokens platform linked to 12,000 compromised accounts
Microsoft said it led an industry-wide disruption of EvilTokens, a platform linked to the compromise of 12,000 accounts at 10,000 organizations over several months. UK police arrested two men, while 50 websites and 150 additional domains were seized through legal action.
Microsoft said it led an industry-wide operation against EvilTokens, a platform that automated mass attacks on Microsoft accounts. Over several months, users of the service compromised 12,000 accounts belonging to 10,000 organizations worldwide.
The subscription service charged an initial $1,500 fee and $500 per month. Microsoft said it seized 50 websites and 150 additional domains tied to the platform; Britain’s Metropolitan Police Service arrested two men on suspicion of offenses allegedly connected to it.
AI analyzed compromised inboxes
EvilTokens was introduced through a Telegram channel in February. The platform analyzed up to 5,000 compromised emails at a time, identified employees authorized to approve large payments and generated scenarios for diverting funds to attacker-controlled accounts.
Microsoft said the embedded chatbot also identified trusted contacts, payment authorities and other circumstances that could make fraud more likely to succeed. It helped users draft messages impersonating trusted people.
OAuth device codes enabled access
The attacks used legitimate OAuth device-code authentication, a process designed in part for TVs and other devices with limited input. After a victim followed a malicious link, the victim was shown a code and instructed to enter it on Microsoft’s official sign-in portal, allowing the attacker to enroll a device.
The platform automated bulk spam delivery, dynamic code generation and post-compromise activity. SpyCloud, which assisted Microsoft’s operation, identified the identity provider as Microsoft Entra.
The largest concentration of affected organizations was in the US, followed by Canada, the UK, Australia, India and France. Victims included organizations in wholesale distribution, construction, financial services, real estate, higher education and healthcare.
Microsoft said attackers may understand a compromised inbox within minutes. The company advised organizations to strengthen identity protections and independently verify requests to change payment details, redirect funds or approve unusual transactions.
What we know
- EvilTokens was linked to 12,000 compromised accounts at 10,000 organizations.
- Microsoft seized 50 websites and 150 additional domains tied to the platform.
- The service analyzed up to 5,000 compromised emails at a time.
- UK police arrested two men in connection with the alleged crime platform.
What is being verified
- The newsroom is checking the report that evilTokens was linked to 12,000 compromised accounts at 10,000 organizations.
- Reporting from Ars Technica is being compared; a second independent confirmation is not yet available.
View sources1
COMMUNITY
Discussion
Sign in to join the discussion.

No comments yet. Start the discussion.