344
Productivity & Workflow355
Automation & Workflow225
Software Development251
Marketing & Growth192
AI Infrastructure & MLOps175
Writing & Content Creation203
Data & Analytics142
Photography & Imaging156
Design & Creative170
Customer Support133
Sales & Outreach125
Voice & Speech135
Education & Learning131
Operations & Admin87
Microsoft says it helped shut down EvilTokens, a paid scam service that used an AI chatbot and trick logins to break into thousands of Microsoft accounts.
In short: Microsoft says it helped disrupt a paid scam platform called EvilTokens that used an AI chatbot to break into about 12,000 Microsoft accounts.
Microsoft said it led a group of partners in taking down EvilTokens, a subscription service sold to criminals through Telegram. Microsoft said the service helped criminals compromise accounts at about 10,000 organizations worldwide over a few months, with the largest number of victims in the US.
According to Microsoft, EvilTokens charged $1,500 up front and $500 per month. It offered an end-to-end package that made it easier to break into many email accounts and then use those inboxes to plan fraud. The AI chatbot could scan a victim’s emails and point out trusted contacts, payment approvals, and who inside a company might be able to move money.
Microsoft said it used legal steps and help from partners to seize 50 websites and 150 other internet domains linked to EvilTokens. The UK’s Metropolitan Police Service arrested two men on suspicion of offenses connected to the platform.
The scam relied on “device code authentication,” a real Microsoft login method meant for devices like TVs that are hard to type on. In simple terms, victims were tricked into entering a code on an official Microsoft sign-in page, which ended up approving access for the attacker’s device, like handing someone a spare key because they asked in a convincing way.
This shows how AI tools can speed up old-fashioned scams. Microsoft warned that once an inbox is compromised, criminals may understand what is going on inside a business in minutes, not days. It also advised organizations to double-check requests to change payment details or send money using a second trusted method, like calling a known phone number.
Source: Arstechnica