Industry·
Microsoft Disrupts AI-Powered EvilTokens Platform That Compromised 12,000 Accounts
Microsoft led a coordinated takedown of a subscription service that used an AI chatbot to automate credential theft via device‑code OAuth, affecting thousands of organizations worldwide.

In February 2026 a new service called EvilTokens appeared on a Telegram channel, offering a subscription model with an upfront fee of $1,500 and a recurring $500 monthly charge. The platform marketed itself as an end‑to‑end toolkit for compromising email accounts at scale.
At the core of EvilTokens was an AI‑style chatbot that could read a victim’s inbox, highlight trusted contacts, payment approvals, and other high‑value signals, then suggest fraud tactics and even draft convincing impersonation messages to trick employees into transferring funds.
Technical abuse of device‑code flow
The attackers abused the legitimate device‑code OAuth flow, which is intended for TVs and other input‑constrained devices. EvilTokens automated the delivery of spam emails containing malicious links; when a recipient clicked, a hidden script interacted with Microsoft Entra ID in real time to generate a device code that the attacker could use to enroll a rogue device.
Microsoft, together with partners such as SpyCloud and the UK Metropolitan Police, seized 50 websites and 150 domains linked to the service and arrested two suspects. Approximately 12,000 Microsoft accounts belonging to 10,000 organizations across the US, Canada, UK, Australia, India, and France were compromised, spanning sectors like finance, healthcare, construction, and education. This incident underscores how AI can accelerate credential‑theft campaigns and highlights the need for hardened identity controls, real‑time anomaly detection, and continuous monitoring of OAuth‑based authentication mechanisms in GPU‑centric AI infrastructures.
- aigpu
- ai gpu
- ai gpu cloud
- aigpu dubai
- microsoft
- eviltokens
- ai-threat
- oauth-security
- cloud-identity
By AiGpu Editorial · Editorial rewrite based on public reporting (Ars Technica)
← All articles