Microsoft disrupts AI-assisted platform that compromised 12,000 accounts

Microsoft disrupts AI-assisted platform that compromised 12,000 accounts

Ars Technica business

Key Points:

  • Microsoft led a coordinated effort to disrupt EvilTokens, a subscription-based scam platform that used an AI chatbot to compromise 12,000 Microsoft accounts across 10,000 organizations globally, primarily in the US, Canada, the UK, Australia, India, and France.
  • EvilTokens charged users an initial $1,500 fee plus $500 monthly, automating the entire email compromise process, including analyzing inboxes, identifying high-value targets, and drafting convincing phishing emails to trick employees into transferring funds to attacker-controlled accounts.
  • The platform exploited a legitimate OAuth device code authentication process by directing victims to enter attacker-generated codes, enabling unauthorized device enrollment and bypassing traditional security detections through complex backend automation.
  • AI capabilities allowed EvilTokens to rapidly analyze thousands of compromised emails to map organizational hierarchies and identify employees authorized to disburse funds, significantly accelerating fraud execution compared to traditional methods.
  • Microsoft seized 50 websites and 150 domains linked to EvilTokens and, with law enforcement partners including the UK’s Metropolitan Police, arrested two suspects; the company emphasized the need for strong identity protections and independent verification of financial requests within organizations.

Trending Business

Trending Technology

Trending Health