Hackers Used AI to Pick Victims From Stolen Emails: Microsoft Takes Down 200+ Sites and Domains

The platform allegedly analysed stolen emails, mapped financial relationships and exploited Microsoft’s device-code login system to support targeted payment scams

Microsoft
Microsoft has disrupted EvilTokens, an alleged cybercrime platform that used AI to analyse stolen inboxes and help hackers identify potential fraud targets Pexels

Microsoft has dismantled EvilTokens, a cybercrime platform that allegedly helped criminals turn hacked email accounts into targeted fraud campaigns. The service was linked to more than 12,000 compromised accounts across over 10,000 organisations in several countries.

The company said the platform was particularly concerning because AI was not simply being used to write convincing scam messages. It was helping attackers work out who to target, who to impersonate and how to exploit those relationships.

How EvilTokens Turned Hacked Inboxes Into a Fraud Tool

EvilTokens reportedly appeared on Telegram in February, offering criminals access to a ready-made cybercrime service. Customers paid $1,500 upfront, followed by a monthly fee of $500.

Once an account was compromised, the platform could search through the victim's inbox for valuable information, including financial discussions, payment responsibilities and relationships with colleagues or business partners.

The AI chatbot could then help identify people who might be persuaded to authorise payments or transfer money. That turned a stolen inbox into something far more valuable than a collection of emails.

Hackers Exploited a Legitimate Microsoft Login System

EvilTokens reportedly abused Microsoft's legitimate device-code authentication system. The feature is designed for devices that do not have a conventional web browser, but criminals allegedly used it as part of phishing attacks.

Potential victims were sent links or instructions directing them to enter a device code on Microsoft's genuine login page. Behind the scenes, attackers could use the authentication process to gain access to the victim's account. The technique was particularly useful because the victim could be interacting with a legitimate Microsoft page while unknowingly helping an attacker authenticate.

AI Helped Criminals Choose Their Victims

After gaining access, attackers could use EvilTokens' chatbot to analyse the contents of compromised mailboxes. Microsoft said the AI could identify people with financial authority, uncover trusted relationships and find information that could make a fraudulent request appear legitimate.

It could then recommend approaches and generate messages designed to impersonate someone the target already trusted.

'AI was not simply helping attackers write more convincing messages. It helped them decide who to target, who to impersonate, and how to most effectively exploit the relationship to extract as much money as possible,' Microsoft said.

Instead, it was helping them decide who to target, who to impersonate and how to exploit the relationship.

More Than 12,000 Accounts Compromised

Microsoft said activity linked to EvilTokens was concentrated in the US, UK, Canada, Australia, India and France. Victims included organisations in financial services, healthcare, construction, real estate, higher education and wholesale distribution.

The company worked with partners to seize 50 websites connected to the operation and disable more than 150 additional domains supporting its infrastructure.

The alleged operation has also led to arrests in Britain. Microsoft said the Metropolitan Police's cybercrime team arrested two men in connection with the investigation.

The arrests followed Microsoft's work with law enforcement and came as authorities investigated the people allegedly behind the service. The investigation remains ongoing.

EvilTokens Shows How AI Is Changing Cybercrime

The biggest warning from the operation is not simply that criminals are using AI to write better phishing emails. EvilTokens attempted to automate the decision-making that comes after an account has been stolen.

Instead of forcing criminals to manually search thousands of emails and work out who has the authority to move money, the platform could use AI to analyse that information and point attackers towards potentially lucrative targets.

Microsoft's disruption has shut down the infrastructure behind EvilTokens, but the techniques involved, phishing, account takeovers, legitimate authentication systems and AI-assisted analysis, can be used independently.