A major cybercrime takedown has highlighted how AI is making phishing and financial fraud easier to organise, with EvilTokens linked to more than 12,000 compromised Microsoft 365 inboxes across over 10,000 organisations worldwide.
Since February 2026, EvilTokens operated as a subscription-based phishing-as-a-service platform. It combined account compromise, mailbox analysis, target selection and fraud preparation through a central dashboard and chatbot. The service charged $1,500 as an initial fee and $500 per month and was promoted through Telegram channels.
“EvilTokens combined account compromise, mailbox analysis, target selection, and fraud preparation in a single service,” Microsoft said. “Capabilities that once required experience across identity attacks, cloud systems, social engineering, and financial fraud were available through a ready-made interface.”
The platform exploited Microsoft’s OAuth 2.0 device-code authentication flow to steal valid session tokens. Victims were shown a short-lived authentication code and tricked into entering it on the legitimate Microsoft device login page. This allowed attackers to access email accounts without obtaining passwords.
The stolen tokens also helped criminals maintain access to Microsoft 365 and Entra ID accounts after legitimate sign-in.
AI chatbot helped identify fraud opportunities
EvilTokens also offered an AI-powered “analyst” chatbot that scanned compromised inboxes for potential financial fraud, including business email compromise.
Jason Rivera, global field CISO at SimSpace, said: “EvilTokens uses tailored phishing messages to trick victims into authorizing attacker access through Microsoft’s legitimate sign-in process.”
He added: “It [EvilTokens] then recommends impersonation targets and helps draft fraudulent messages grounded in actual business conversations. Automated reconnaissance maps organizational permissions, while token refresh and inbox monitoring help maintain access and surface new opportunities.”
Targeted organisations included businesses in wholesale distribution, construction, financial services, real estate, higher education and healthcare across North America, the UK, France, India and Australia.
Coinbase traced about $1.1 million in revenue from more than 700 cryptocurrency addresses linked to the operation.
A US federal court order allowed the seizure of 50 websites and more than 150 related domains. UK police also arrested 2 men, aged 32 and 38, suspected of running the technology and infrastructure. Both were released on police bail pending further investigation.
Omair Manzoor of ioSENTRIX said the “takedown was successful because the operators made a classic infrastructure mistake — centralizable domains and traceable crypto payments.”
He warned that similar scams could emerge and said, “Organizations need to assume that every compromised mailbox will be read and exploited by AI within minutes, not days.”
He also called for device-code phishing protections, including conditional access controls, shorter token lifetimes and alerts for unusual authentication activity, to become standard security measures.
Also read: Viksit Workforce for a Viksit Bharat
Do Follow: The Mainstream LinkedIn | The Mainstream Facebook | The Mainstream Youtube | The Mainstream Twitter
About us:
The Mainstream is a premier platform delivering the latest updates and informed perspectives across the technology business and cyber landscape. Built on research-driven, thought leadership and original intellectual property, The Mainstream also curates summits & conferences that convene decision makers to explore how technology reshapes industries and leadership. With a growing presence in India and globally across the Middle East, Africa, ASEAN, the USA, the UK and Australia, The Mainstream carries a vision to bring the latest happenings and insights to 8.2 billion people and to place technology at the centre of conversation for leaders navigating the future.


