READ. SCROLL. LISTEN.

Unbiased headlines. Facts, not spin.

Every story is an unbiased news briefing written from 113+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Microsoft and Partners Take Down EvilTokens, an AI Chatbot Sold on Telegram to Hack 12,000 Accounts

Microsoft and Partners Take Down EvilTokens, an AI Chatbot Sold on Telegram to Hack 12,000 Accounts
Since launching on Telegram in February 2026, EvilTokens sold cybercriminals an AI chatbot that scanned stolen inboxes for the best fraud targets. Microsoft, working with Cloudflare, Coinbase, OpenAI and others under a federal court order, seized dozens of sites and got two UK men arrested. Confirmed reported losses so far: $1.7 million, which Microsoft itself calls a low estimate given 12,000 compromised accounts.

Since its debut on a Telegram channel in February 2026, a phishing-as-a-service platform called EvilTokens grew into one of the more widely used tools for business email compromise before Microsoft and eight partner organizations shut it down this month.

Microsoft announced the disruption Tuesday, September 22, 2026. The company said EvilTokens charged customers a $1,500 setup fee plus $500 a month for access to a bundled hacking kit: stolen account access, an AI chatbot, and fraud scripts, all in one subscription.

What the AI actually did

According to Steven Masada, associate general counsel and general manager of Microsoft's Digital Crimes Unit, the chatbot at the center of EvilTokens didn't just write phishing emails. It read through a victim's actual inbox after criminals broke in, then flagged trusted contacts, payment authorizations, and other details useful for a con.

"AI was not simply helping attackers write more convincing messages," Masada wrote in a Microsoft blog post. "It helped them decide who to target, who to impersonate, and how to most effectively exploit the relationship to extract as much money as possible."

The break-ins themselves relied on a legitimate Microsoft sign-in feature called device code authentication, built for TVs and other gadgets without normal keyboards. Attackers tricked victims into entering a code on Microsoft's own login page, handing over an active session without ever needing a password.

Scale of the damage

Microsoft says EvilTokens compromised roughly 12,000 accounts across more than 10,000 organizations worldwide, hitting wholesale distribution, construction, financial services, real estate, higher education and healthcare businesses. The U.S. had the highest concentration of victims, followed by Canada, the UK, Australia, India and France. SpyCloud, which assisted the takedown, found compromised email domains spanning 79 countries.

CyberScoop reported that about 1,000 cybercriminals used the platform over its run, citing a Microsoft spokesperson. Despite that reach, Microsoft could only tie specific dollar losses to a small slice of victims: at least 13 complaints filed with the FBI's Internet Crime Complaint Center, representing roughly $1.7 million in reported losses. A Microsoft spokesperson told CyberScoop that figure is "a conservative estimate" because many incidents go unreported and not every victim can be definitively linked to an EvilTokens campaign.

The takedown

Acting on a September 15, 2026 order from the U.S. District Court for the Eastern District of Virginia, Microsoft seized 50 websites used to run EvilTokens. Ars Technica and Microsoft's own blog post both put the number of disabled supporting domains at more than 150. CyberScoop, citing the company, reported a higher figure of more than 175 disabled domains. Neither Microsoft's public statement nor the other outlets explained the gap, but it points to some inconsistency in how the company characterized the operation's footprint across its own disclosures.

The operation involved Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation and TRM Labs, according to The Hacker News. Microsoft is tracking the developers behind the platform as Storm-2992, which it describes as unaffiliated with any other known cybercrime group.

On September 11, 2026, London's Metropolitan Police Service arrested two men, ages 32 and 38, on suspicion of offenses connected to running EvilTokens. Microsoft identified the pair in its own reporting as Felix Utomi and Waidi Segun Adams, per CyberScoop. No U.S. charges have been announced against either man, and as of this writing neither has been convicted of anything. These remain allegations tied to an active law enforcement action, not proven criminal conduct.

Timeline questions

Security researchers flagged this scheme long before Microsoft acted. The Hacker News reported that Huntress first documented EvilTokens' abuse of Microsoft's device code authentication flow in March 2026, and Sekoia published a similar report describing it as a turnkey Telegram-sold service that same month.

A fair question: why did a known abuse pattern, publicly documented by two separate security firms in March, keep running until a court order in mid-September, roughly six months later? Microsoft's public materials don't address that gap directly, and none of the coverage reviewed here quotes anyone at Microsoft explaining the timeline between the March research and the September legal action.

Building a case that survives a federal court and coordinates arrests across two countries takes time, and Microsoft's disclosures don't suggest it sat on the information. But the lag between public documentation and takedown is the kind of question Congress or industry auditors could reasonably put to Microsoft directly, and none of the current reporting says anyone has.

What's confirmed: two arrests, 50 seized sites, more than 150 disabled domains, and $1.7 million in documented fraud tied to 12,000 compromised accounts. What's unresolved: the true financial toll, whether any of the roughly 1,000 platform users beyond the two UK suspects will face charges, and why a documented device-code abuse pattern from March took until September to shut down.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center
CyberScoopMicrosoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud
center-left
Ars TechnicaMicrosoft disrupts AI-assisted platform that compromised 12,000 accounts
unknown
daily.devMicrosoft disrupts AI-assisted platform that compromised 12,000
unknown
Data World BankMicrosoft disrupts AI-assisted platform that compromised 12,000 - Technology data bank
unknown
unknownMicrosoft Leads Disruption of AI-Powered Scam Platform Compromising 12,000 Accounts
unknown
The Hacker NewsMicrosoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
unknown
blogs.microsoftDisrupting EvilTokens: The AI Chatbot Built for Cybercrime - Microsoft On the Issues