NewsCybersecurityAI AbusePhishing

Microsoft Shuts Down Eviltokens AI-Powered Phishing Service Behind 12,000 Compromised Accounts

A phishing service called Eviltokens used AI to compromise Microsoft accounts across 10,000+ organizations in just months—without stealing passwords. Microsoft has now taken down the operation.

12,000 accounts from 10,000+ organizations compromised

Microsoft Shuts Down Eviltokens AI-Powered Phishing Service Behind 12,000 Compromised Accounts

Microsoft has dismantled a large-scale AI-powered phishing service named Eviltokens that compromised over 12,000 accounts belonging to more than 10,000 organizations within a matter of months. Remarkably, the attackers never needed to steal passwords. Instead, they leveraged AI models to automate and scale their campaigns—marking a new level of cyber threat sophistication.

Key Facts

  • 12,000 Microsoft accounts from over 10,000 organizations were compromised
  • Attackers used AI models to automate phishing campaigns
  • No password theft required—attackers targeted authentication tokens instead
  • The operation ran for several months before Microsoft shut it down

How Eviltokens Operated

The service followed a proven attack pattern: rather than cracking passwords, attackers targeted authentication tokens—digital keys that users automatically receive upon login. These tokens often remain valid longer than a single session, granting access without re-authentication.

AI was central to scaling the operation. Instead of manually crafting phishing emails and selecting targets, the operators used AI models to optimize and personalize campaigns. This enabled them to compromise tens of thousands of accounts in a short timeframe.

Escalation of AI Abuse Risks

Eviltokens is not an isolated case. Security researchers simultaneously report similar patterns: the malware project ClosedQuorum uses multiple AI models—including Google Gemini, DeepSeek, Qwen, and Mistral—to guide and adapt cyberattacks in real time. These developments show that AI misuse is no longer theoretical but operationally active in cybercriminal activity.

Microsoft has now dismantled Eviltokens' infrastructure and is collaborating with law enforcement. Affected organizations have been notified.

Implications for Enterprises

The Eviltokens operation is a wake-up call for organizations worldwide. Token-based attacks are difficult to detect because they leave no password-change traces and often evade standard security systems. Companies must prioritize multi-factor authentication, shorten token lifecycles, and monitor access pattern anomalies. At the same time, AI-driven attacks are becoming faster and more precise—traditional defenses alone are insufficient. Investment in AI-powered threat detection is shifting from optional to essential.

Sources

Editorially owned by Ideal Syka. Sources and method: Newsroom & method. Tips and corrections: ai@i6eal.de.

Share
← All articles

All analyses are based on i6eal's own measurements or on clearly labelled sources. Figures are snapshots and may change; corrections are disclosed transparently.