Microsoft says a subscription scam platform used an AI-style chatbot to analyze compromised inboxes and identify employees who could authorize large payments. EvilTokens allegedly helped customers turn stolen Microsoft accounts into tailored business-email fraud, shrinking work that once took days into minutes.

The service automated spam delivery and abused Microsoft’s legitimate device-code login flow. Victims were directed to an official login portal and persuaded to enter a code that enrolled an attacker-controlled device. After access was gained, EvilTokens could process thousands of emails, map managers and business partners, and draft plausible requests to redirect funds.

Microsoft says the operation compromised 12,000 accounts at 10,000 organizations over several months. Using legal orders and help from security partners, the company seized 50 websites and another 150 domains connected to the service. London’s Metropolitan Police arrested two men on suspicion of related offenses; those allegations have not yet been tested in court.

The case changes the practical risk of an inbox breach. Attackers no longer need to manually learn a company’s payment relationships before impersonating a trusted contact. Microsoft recommends independently verifying unusual transfers or changes to payment instructions through a separate, trusted channel.