Microsoft says it led an industry-wide takedown of EvilTokens, a subscription platform that used an AI chatbot to help criminals compromise 12,000 Microsoft accounts over a few months.
The service appeared on a Telegram channel in February with a straightforward price list. Customers paid $1,500 to start and $500 a month after that, and in return got a single dashboard that handled most of the work of stealing email accounts at scale.
Its features followed the arc of a real intrusion rather than a phishing kit. EvilTokens helped buyers analyse inboxes for material worth stealing, rank targets by how much money they could be made to part with, and draft convincing messages in the victim’s own voice and style.
Microsoft described the platform as providing an end-to-end capability that made mass compromise faster and easier, which is the same shift security researchers have been tracking across the criminal market this year. Large language models remove the language barrier that once limited phishing to attackers who could write convincingly in a target’s language.
The disruption is one operation against a market that keeps reconstituting itself. Microsoft has run similar campaigns before, and each takedown removes a brand rather than the underlying model access that any competent developer can rent.