Microsoft Dismantles AI‑Driven Scam That Breached 12,000 Accounts

1 min read
Source: Ars Technica
Microsoft Dismantles AI‑Driven Scam That Breached 12,000 Accounts
Photo: Ars Technica
TL;DR Summary

Microsoft led an industry-wide takedown of EvilTokens, an AI-assisted platform that automated mass email compromises, using a device-code OAuth workflow to hijack Microsoft accounts and identify high‑value targets. The service compromised about 12,000 accounts across 10,000 organizations before authorities seized 50 sites and 150 domains and the UK arrested two men. The incident underscores the need for strong identity protections and independent verification of payment-change requests.

Share this article

Reading Insights

Total Reads

0

Unique Readers

7

Time Saved

5 min

vs 5 min read

Condensed

93%

98866 words

Want the full story? Read the original article

Read on Ars Technica