Microsoft and Partners Take Down Fraud Service Tied to 12,000 Accounts

The criminals behind the platform did not need to write their own code. For a subscription fee, “EvilTokens” sold them the tools to break into Microsoft accounts, a service built partly on AI chatbots that did the social engineering for them.

Microsoft said this week that it worked with industry partners to dismantle the subscription-based fraud operation, which it said helped cybercriminals compromise roughly 12,000 Microsoft accounts over a span of months. Coinbase provided the key leads, and two people have been arrested in the United Kingdom, according to people familiar with the matter.

The takedown is the latest example of how artificial intelligence has lowered the cost of entry to cybercrime. What once required a skilled attacker to write phishing pages and manage conversations with victims can now be rented, with chatbots handling the persuasion and the platform supplying the infrastructure. The result is volume: 12,000 accounts in months, rather than the slow, hand-run campaigns of a decade ago.

The service relied in part on a technique known as device-code phishing, according to security researchers. In that method, an attacker initiates a sign-in on Microsoft’s legitimate device-authorization flow and gets a short code, then persuades the victim to enter the code on Microsoft’s own login page. Because the victim completes a genuine sign-in, often including multifactor authentication, the completed session belongs to the attacker.

That approach has bedeviled defenders because it does not look like ordinary phishing. The victim lands on a real Microsoft page, enters real credentials and approves a real prompt, yet the resulting tokens go to a device the attacker controls. Security vendors have documented the method repeatedly over the past year, warning that it bypasses the password hygiene that most companies rely on.

Microsoft has been tracking this method under its own threat-intelligence naming for more than a year, and it has told administrators that device-code authentication is a higher-risk flow that should be blocked wherever it is not required. The company’s guidance predates EvilTokens, but the takedown suggests the problem has kept growing even as the defenses tightened.

Coinbase’s role in the case shows how cryptocurrency platforms have become an unexpected front line in account-takeover investigations. Fraudsters who steal access to email accounts often move quickly to drain the crypto accounts linked to them, which gives exchanges a financial incentive and the transaction data to trace the attacks. In this case, that trail led investigators to the operation and, eventually, to arrests in Britain.

The 12,000 figure matters because each account is a node in a larger fraud. A compromised email account gives an attacker the keys to password resets, financial logins and the crypto wallets tied to the inbox. Investigators often find that a single stolen account cascades into several losses before the owner notices.

Microsoft has spent the year wrestling with a surge in identity-based attacks. The company has pushed organizations toward passwordless sign-in and stricter conditional-access policies, and it has told administrators to block device-code authentication where it is not needed. The takedown fits that broader campaign, in which Microsoft has become both a target and a security vendor for the same customers.

The subscription model is what made EvilTokens notable, analysts said. Rather than selling stolen data after the fact, the platform sold the means of theft up front, a shift that turns hacking into a recurring-revenue business and attracts operators who would never have built the tools themselves. The AI chatbot layer made the service usable by people with little technical skill.

Law enforcement’s arrests in the United Kingdom suggest the case may produce prosecutions, though the charges and the defendants’ identities have not been disclosed. Cross-border takedowns of this kind rarely end with the platform alone; investigators typically follow the subscriber list to identify the individual breaches the service enabled.

The economics of the defense remain lopsided. A subscription service can attack thousands of accounts while its operators never touch a victim directly, and the victims are often small businesses and individuals who lack dedicated security staff. The 12,000 compromised accounts are the ones Microsoft can count; the full number of people who lost email, files or money is likely higher.

Microsoft said the disruption is part of a sustained effort against the infrastructure that makes this kind of fraud possible, rather than a single raid. The company has taken similar action against phishing-as-a-service operations over the past two years, in some cases working with the same coalition of exchanges, security firms and law enforcement that helped in this case.

The incident will not be the last of its kind. As long as a legitimate authentication flow can be turned against its user, and as long as chatbots can do the talking, the barrier to entry will keep falling. The takedown removed one platform from the market. The conditions that produced it are still in place.

Related Posts

  • September 23, 2026
  • 14 views
Anthropic and OpenEvidence to Give Free Medical AI to Poorer Countries

OpenEvidence began as a way for a doctor to ask a question and get an answer drawn from peer-reviewed research rather than a search engine. It is free for clinicians…

  • September 23, 2026
  • 18 views
Meta’s Muse Tops the Charts, Then Runs Into Amazon

Meta released Muse on Sept. 8 with a simple pitch: a personal AI agent that could book tickets, sort email and act across the web on a user’s behalf. The…