<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/microsoft-disrupts-ai-assisted-platform-that-compromised-12-000-uwizsmwis" -->

---
title: Microsoft disrupts AI-assisted platform that compromised...
description: Microsoft led an industry-wide takedown of EvilTokens, a subscription-based phishing-as-a-service platform that used an AI chatbot to analyze victim inboxes...
canonical: https://daily.dev/posts/microsoft-disrupts-ai-assisted-platform-that-compromised-12-000-uwizsmwis
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Microsoft disrupts AI-assisted platform that compromised 12,000 | daily.dev
og:description: Microsoft led an industry-wide takedown of EvilTokens, a subscription-based phishing-as-a-service platform that used an AI chatbot to analyze victim inboxes...
og:url: https://daily.dev/posts/microsoft-disrupts-ai-assisted-platform-that-compromised-12-000-uwizsmwis
og:image: https://api.daily.dev/og/posts/UwizSmWiS.png
og:image:alt: Microsoft disrupts AI-assisted platform that compromised 12,000
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Microsoft disrupts AI-assisted platform that compromised 12,000

**[Ars Technica](https://daily.dev/sources/arstechnica)** · 2 min read · 0 upvotes · 0 comments

## Summary

Microsoft led an industry-wide takedown of EvilTokens, a subscription-based phishing-as-a-service platform that used an AI chatbot to analyze victim inboxes and help criminals identify high-value targets and craft convincing fraud emails. The platform, sold via Telegram for a $1,500 setup fee plus $500 monthly, compromised 12,000 Microsoft accounts across 10,000 organizations worldwide, mostly in the US, using abuse of OAuth device code authentication. Microsoft seized 50 websites and 150 domains, and UK police arrested two suspects.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://arstechnica.com/security/2026/09/microsoft-disrupts-ai-assisted-platform-that-compromised-12000>

## Questions this post answers

### What is EvilTokens and how did it use AI to compromise Microsoft accounts?

EvilTokens was a subscription-based phishing-as-a-service platform sold on Telegram starting in February, charging a $1,500 initial fee plus $500 monthly. It used an AI-style chatbot to analyze victims' inboxes, identify trusted relationships and payment authorizations, and draft impersonation emails to trick employees into wiring funds. It compromised 12,000 Microsoft accounts across 10,000 organizations, mostly in the US, before Microsoft seized 50 websites and 150 domains and UK police arrested two suspects.

_daily.dev surfaces security research like this for teams hardening identity and email defenses._

### How did attackers abuse OAuth device code authentication to compromise Microsoft accounts?

Attackers exploited device code authentication, an OAuth flow meant for TVs and input-constrained devices that lack normal login interfaces. In this flow, a device displays a code that the user enters into a browser on a separate device to authenticate; criminals using the EvilTokens platform abused this legitimate process to gain unauthorized access to victims' Microsoft accounts.

_Developers implementing OAuth device flows can follow evolving abuse patterns via daily.dev._

---

Tags: [#microsoft](https://daily.dev/tags/microsoft), [#phishing](https://daily.dev/tags/phishing), [#ai-security](https://daily.dev/tags/ai-security), [#oauth](https://daily.dev/tags/oauth)

[View this post on daily.dev](https://daily.dev/posts/microsoft-disrupts-ai-assisted-platform-that-compromised-12-000-uwizsmwis)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Microsoft disrupts AI-assisted platform that compromised 12,000","url":"https://daily.dev/posts/microsoft-disrupts-ai-assisted-platform-that-compromised-12-000-uwizsmwis","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/microsoft-disrupts-ai-assisted-platform-that-compromised-12-000-uwizsmwis"},"datePublished":"2026-09-22T20:02:00.618Z","dateModified":"2026-09-22T21:06:30.820Z","description":"Microsoft led an industry-wide takedown of EvilTokens, a subscription-based phishing-as-a-service platform that used an AI chatbot to analyze victim inboxes...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/a696f9fde49ed609fee091dd6d1512db?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/a696f9fde49ed609fee091dd6d1512db?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Ars Technica","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Ars Technica","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/80883e0e48a34b5ebcf93777016cb3fe","url":"https://daily.dev/sources/arstechnica"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/microsoft-disrupts-ai-assisted-platform-that-compromised-12-000-uwizsmwis","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"microsoft,phishing,ai-security,oauth","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Ars Technica","item":"https://daily.dev/sources/arstechnica"},{"@type":"ListItem","position":3,"name":"Microsoft disrupts AI-assisted platform that compromised 12,000"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/microsoft-disrupts-ai-assisted-platform-that-compromised-12-000-uwizsmwis#faq","mainEntity":[{"@type":"Question","name":"What is EvilTokens and how did it use AI to compromise Microsoft accounts?","acceptedAnswer":{"@type":"Answer","text":"EvilTokens was a subscription-based phishing-as-a-service platform sold on Telegram starting in February, charging a $1,500 initial fee plus $500 monthly. It used an AI-style chatbot to analyze victims' inboxes, identify trusted relationships and payment authorizations, and draft impersonation emails to trick employees into wiring funds. It compromised 12,000 Microsoft accounts across 10,000 organizations, mostly in the US, before Microsoft seized 50 websites and 150 domains and UK police arrested two suspects. daily.dev surfaces security research like this for teams hardening identity and email defenses."}},{"@type":"Question","name":"How did attackers abuse OAuth device code authentication to compromise Microsoft accounts?","acceptedAnswer":{"@type":"Answer","text":"Attackers exploited device code authentication, an OAuth flow meant for TVs and input-constrained devices that lack normal login interfaces. In this flow, a device displays a code that the user enters into a browser on a separate device to authenticate; criminals using the EvilTokens platform abused this legitimate process to gain unauthorized access to victims' Microsoft accounts. Developers implementing OAuth device flows can follow evolving abuse patterns via daily.dev."}}]}
```

