Skip to content
logo The magazine for digital lifestyle and entertainment
Fraud Microsoft News Security All topics
More than 12,000 Victims

Microsoft Dismantles Dangerous AI Attack Platform

Graphical Representation of AI-Powered Phishing: In the center, a glowing AI symbol surrounded by email, login, and search icons on fishing hooks against a blue background
The fraudulent platform EvilTokens used AI to analyze hijacked email accounts and prepare new phishing attacks. Photo: Getty Images

September 27, 2026, 2:04 pm | Read time: 3 minutes

a {<br> text-decoration: none;<br> color: #464feb;<br>}tr th, tr td {<br> border: 1px solid #e6e6e6;<br>}tr th {<br> background-coMicrosoft has taken action against an international fraud network that allegedly operated an AI-powered platform for phishing attacks. According to Microsoft, the service, named EvilTokens, has been used since February 2026 to compromise email accounts worldwide. More than 12,000 mailboxes across over 10,000 organizations were affected, according to the company. Two suspected operators were arrested in the United Kingdom.

Microsoft Takes Action Against Fraud Platform

As Microsoft announced, the Digital Crimes Unit seized 50 websites belonging to the EvilTokens infrastructure with a court order. Additionally, more than 150 other domains were deactivated. This was intended to largely dismantle the technical foundation of the service.

EvilTokens was offered as a so-called Phishing-as-a-Service (PaaS) via Telegram. Criminals could gain access to the platform for a fee. Initially, a fee of $1,500 was required. Subsequently, the operators charged an additional $500 monthly.

How Attackers Gained Access to Accounts

According to Microsoft, the platform exploited a vulnerability in the “Device Code Authentication.” This method is actually intended for devices where input is only possible to a limited extent.

The victims received phishing messages with a link to a manipulated website. There, a code was generated that they were supposed to enter on a legitimate Microsoft login page. This allowed the attackers to access the accounts. According to Microsoft, the method worked even when two-factor authentication was enabled.

Phishing attacks are constantly evolving. Current data shows that criminals in Germany increasingly rely on well-known domestic brands. According to the available data, the Techniker Krankenkasse is now more frequently misused for phishing attacks than Amazon or Microsoft.

More on the topic

AI Automatically Analyzed Mailboxes

EvilTokens differed from many other phishing offerings primarily through the use of artificial intelligence. An AI chatbot automatically searched compromised mailboxes for relevant information.

The system searched, among other things, for employees with payment authorizations, ongoing business transactions, and sensitive data. The AI then used the collected information to create fraudulent messages and send them to colleagues or business partners of the affected individuals.

Steven Masada from Microsoft’s Digital Crimes Unit stated that companies must assume that criminals could understand the content of a compromised mailbox within minutes. According to Microsoft, the platform used AI to complete tasks within a few hours that previously took criminals several days.

Investigators Track Millions in Financial Flows

The crypto company Coinbase also participated in the investigations. Payment flows of around $1.1 million between October 2025 and June 2026 were tracked. This corresponds to approximately 963,151 euros.

Also of interest: Microsoft distributes emergency update for Windows 10 and 11

The affected organizations were primarily in the U.S., Canada, UK, Australia, India, and France. The compromised sectors included construction companies, financial service providers, real estate firms, universities, and healthcare facilities. In addition to Microsoft, Cloudflare, Coinbase, OpenAI, SpyCloud, and other partners supported the measures against the network.

Microsoft advises companies to activate Device Code Authentication only where it is truly needed. Additionally, payment instructions should always be verified through a second independent communication channel. Fraud attempts continue to evolve steadily. These include not only phishing emails but also WhatsApp scams or deepfake calls.

This article is a machine translation of the original German version of TECHBOOK and has been reviewed for accuracy and quality by a native speaker. For feedback, please contact us at info@techbook.de.

You have successfully withdrawn your consent to the processing of personal data through tracking and advertising when using this website. You can now consent to data processing again or object to legitimate interests.