Microsoft disrupts AI-assisted platform that compromised 12,000 accounts
EvilTokens provided an end-to-end platform that makes mass compromises faster and easier.

EvilTokens provided an end-to-end platform that makes mass compromises faster and easier.
The short version
- Microsoft said Tuesday that it led an industry-wide disruption of a subscription-based scam platform that used an AI chatbot to compromise 12,000 Microsoft accounts over a few-month span.
- Using a legal process and a network of partners, Microsoft seized 50 websites and 150 more domains used to operate EvilTokens.
- The UK’s Metropolitan Police Service arrested two men on suspicion of offenses allegedly connected to the crime platform.
What happened
Account compromises were achieved through a legitimate OAuth process known as device code authentication . This form of authentication is designed for TVs and input-constrained devices, meaning those that lack the interface for performing normal log-in processes.
Why it matters
In this model, the device being signed into presents a code and instructs the user to enter it into a browser on a separate device.
Summary by Nerd News Network. Read the full article at Ars Technica via the links above and below.
