Microsoft disrupts AI-powered cybercrime service
Add Axios as your preferred source to
see more of our stories on Google.

Illustration: Sarah Grillo/Axios
Microsoft has taken down digital infrastructure tied to a powerful cybercrime platform that relied on AI tools throughout its operations, the company said this morning.
Why it matters: While the AI industry panics about extinction risks that are years away, financially motivated hackers are already using existing AI tools to turn stolen corporate network access into opportunities for fraud.
Driving the news: Microsoft's Digital Crimes Unit obtained authorization from the U.S. District Court for the Eastern District of Virginia to take down infrastructure tied to an AI-enabled cybercrime platform called EvilTokens.
- Working with its industry and law enforcement partners, Microsoft seized 50 websites used to operate the service and disabled more than 150 additional domains tied to its infrastructure.
- British police told Axios in a statement that they arrested two men, aged 32 and 38, earlier this month in connection to EvilTokens.
- The platform helped paying hackers break into email inboxes, then used an AI chatbot to analyze victims' messages, map internal roles, identify trusted relationships and seek out conversations about payments.
- The AI condensed work that could otherwise take hackers several days into hours, helping them determine who controlled the money, whom they trusted and whom to impersonate.
Catch up fast: EvilTokens launched in February when researchers began observing the phishing service successfully compromising Microsoft accounts through a tactic known as device-code phishing.
- Since then, researchers at Microsoft and other cybersecurity firms have tracked EvilTokens as it gained traction among cybercriminals.
- A Microsoft spokesperson told Axios that the company started publicly warning customers about EvilTokens' tactics in April, and then mobilized quickly as they gained deeper visibility into the operations.
- "Once the scale and sophistication of the threat became clear, we moved quickly," the spokesperson added. "In fact, this was a relatively accelerated operation from initiation to execution."
Threat level: Microsoft now estimates that EvilTokens compromised more than 12,000 email inboxes across 10,000 organizations, including those in construction, financial services, real estate, higher education and healthcare.
- Microsoft observed the highest concentrations of victim activity in the U.S., Canada, the UK, Australia, India and France.
- Coinbase, one of the companies that helped Microsoft on the investigation, traced about $1.1 million in revenue to the platform.
How it works: EvilTokens used a subscription model for its platform, charging hackers a $1,500 initiation fee and $500 a month for access.
- Users were given a range of personalized phishing lures to pick from, including those posing as construction bid proposals, business partnership agreements, employee compensation and benefits notices, and password expiration warnings.
- Once a target clicked a malicious link, EvilTokens tricked them into entering a code on Microsoft's legitimate sign-in page that unknowingly granted the hacker access to their account.
- After gaining access, hackers could use EvilTokens' AI tools to sift through the victim's inbox for financial conversations, identify high-value employees and determine whom to impersonate.
- Hackers could then use the compromised account to send additional phishing emails to the victim's internal and external contacts — and used information from the inbox to make their fraud attempts more convincing.
The big picture: EvilTokens is the latest example of how AI models are helping malicious hackers scale and speed up attacks they've long carried out — while lowering the barrier for less-sophisticated hackers to get in the game.
- Microsoft also found evidence that "large portions" of EvilTokens were "vibe coded," or built using AI tools themselves — underscoring how AI was used on both sides of the cybercrime operation, it said today.
- "The same technology was lowering barriers at both ends of the operation: helping criminals build malicious tools more quickly and helping their customers turn compromised accounts into actionable opportunities for fraud," Steven Masada, associate general counsel and general manager in Microsoft's DCU, wrote in a blog post.
What to watch: Law enforcement is conducting its own investigation into EvilTokens, Microsoft said.
