Microsoft disrupts AI-assisted platform that compromised 12,000 accounts
Summary
Microsoft led a joint effort to shut down EvilTokens, an AI-powered scam platform that hacked into 12,000 Microsoft email accounts worldwide. The platform used a legal but unusual sign-in method to take control of accounts and then helped criminals send fake emails to trick companies into paying them money.Key Facts
- EvilTokens was a subscription scam platform sold through Telegram starting in February.
- It charged $1,500 up front and $500 monthly for access.
- The platform used an AI chatbot to analyze victim inboxes and suggest targets and fraud strategies.
- 12,000 Microsoft accounts from 10,000 organizations were compromised, mostly in the U.S., Canada, UK, Australia, India, and France.
- Victims were from industries like finance, healthcare, real estate, education, construction, and wholesale distribution.
- Microsoft and security partners seized 50 websites and 150 domains linked to EvilTokens.
- The UK police arrested two suspects linked to the platform.
- The scam used device code authentication, a method designed for devices like TVs, but tricked users into letting attackers enroll devices they controlled.
Read the Full Article
This is a fact-based summary from The Actual News. Click below to read the complete story directly from the original source.