
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.
Microsoft has made significant strides by taking down EvilTokens, a dangerous subscription service that exploited over 12,000 accounts via advanced AI tools.
Summary
By automating hacking tasks and generating realistic phishing messages from victims' emails, the platform posed a substantial threat. Following the incident, UK authorities apprehended two individuals tied to the scheme, with Microsoft securing multiple associated domains—illustrating a worrying trend that businesses need to urgently confront.
This is a brief wire summary — the full story (linked below) has the complete details.
KazaSec's take
Incidents like this rarely start with the headline event itself — they usually trace back to an exposed remote-access endpoint, an unpatched perimeter system, or a credential phished weeks earlier. The organizations that recover fastest are the ones that tested their defenses and their incident response plan before they needed them.
Coverage details
We've archived 8 other articles touching the same topic (ai in cybercrime, eviltokens cybercrime, microsoft ai chatbot) — see the full security news archive.
Related security advisories
Relevant from KazaSec
More coverage on this topic
We help organizations find and fix the gaps before they make headlines.