Microsoft neutralizes cybercrime platform that used AI to attack over 10,000 organizations
Microsoft recently conducted a large-scale operation to disable the EvilTokens cyber platform. It is a highly advanced tool that has used artificial intelligence in all stages of the attack since its launch in February 2026. The system used artificial intelligence to automatically analyze victims' email inboxes, identify important business contacts, payment authorizations, and craft convincing phishing messages.
Instead of the classic password theft, the platform exploited a trick with confirmation codes on official login pages. This allowed the attackers to gain access to accounts, which remained active even after a possible password change, as long as the sessions and tokens were not canceled. In a matter of minutes, artificial intelligence reviewed thousands of messages, found conversations about transfers, identified key people for approving money, and suggested the best targets. This work, which in the past required a lot of time and expertise, was fully automated by EvilTokens.
The service was sold by criminals through the Telegram app, where the initial fee was approximately €1,250 and the monthly subscription was around €415. The attacks most affected organizations in the US, Canada, the UK, Australia, India and France, in the finance, healthcare, education and construction sectors.
The shutdown involved law enforcement agencies and companies such as Cloudflare, Coinbase, and OpenAI. 50 websites were seized and more than 150 domains were disabled. Two people have already been arrested in the UK in connection with this case. Despite the successful operation, a considerable amount of caution should be maintained, as similar models of AI abuse are spreading rapidly and may reappear in new forms.




















