\n\n\n\n Crime Found Its Product-Market Fit and Microsoft Pulled the Plug - AgntHQ \n

Crime Found Its Product-Market Fit and Microsoft Pulled the Plug

📖 4 min read•752 words•Updated Sep 24, 2026

Microsoft’s Digital Crimes Unit described EvilTokens not as a hacking crew but as a commercial operation — a subscription service that sold account takeovers to anyone willing to pay. Read that framing again, because it’s the whole story. Not a lone genius in a basement. A business, with customers, pricing, and an AI assistant bolted on to make the product easier to use.

On 22 September 2026, Microsoft announced it had disrupted the platform alongside industry partners and law enforcement. The Metropolitan Police Service had already arrested two men, aged 32 and 38, on 11 September. The damage tally: more than 12,000 compromised inboxes across more than 10,000 organizations.

The scariest part is how boring it is

I spend most of my time reviewing AI tools that promise to change how you work and mostly change how much you spend. So I have a professional interest in the rare case where an AI product actually delivers on its pitch. EvilTokens appears to have done exactly that, for the worst possible customers.

The reported design is the part worth sitting with. According to Microsoft, an AI chatbot helped attackers decide which victims to pursue and how to exploit them. That’s not automation of the technical attack. That’s automation of the judgment — the part that used to require experience, patience, and a feel for which target would actually pay off. The chatbot was the senior colleague you’d otherwise need years to become.

Every legitimate AI product company is chasing the same thing. Lower the skill floor. Let a novice ship something a specialist used to ship. EvilTokens ran that playbook against 10,000 organizations.

Device-code phishing, sold by the month

The attack type here was device-code phishing, and it’s a category I wish more people understood before they get hit. These flows exist because logging into a TV or a console with a keyboard is miserable, so you get a short code to enter on a trusted device instead. It’s a legitimate feature. It’s also a feature that produces a valid session without the victim ever typing a password into a fake page.

Which means the standard advice you’ve been repeating for a decade — check the URL, look for the padlock — does approximately nothing. There’s no fake login page to spot. The victim is doing a real thing on a real Microsoft screen, at the wrong person’s request.

Package that technique as a subscription, add a chatbot to handle target selection, and you’ve built something that scales to five figures of victims. The numbers here aren’t impressive because the attack was clever. They’re impressive because the distribution model was good.

What this should change about how you evaluate AI tools

I review agents and AI tools for a living, and my standard skepticism applies in both directions. When a vendor tells me their agent can reason about complex situations and make good calls without hand-holding, I usually find that claim collapses under a real workload. EvilTokens is a data point on the other side: an AI layer doing prioritization and strategy work, at volume, with results measurable in compromised inboxes.

A few things I’d take from this if I ran security at any organization with a Microsoft tenant:

  • Device-code authentication flows deserve an explicit policy. If your users don’t need them, restrict them. If some do, scope it narrowly.
  • User training built around spotting fake login pages is incomplete. The lesson that transfers is procedural — nobody should ever enter a code they didn’t personally initiate, no matter who asked.
  • Assume the attacker on the other end has decent tooling and no particular expertise. The old assumption that sophisticated attacks come from sophisticated people is gone.
  • Treat post-compromise detection as the real control. If credentials and passwords aren’t the gate, anomalous session behavior is where you catch it.

Two arrests, unchanged economics

Credit where it’s earned: coordinating a takedown across a corporate investigations unit, industry partners, and UK police is genuinely hard, and two people are in custody rather than just a domain sitting in a sinkhole. That’s a better outcome than most disruptions produce.

But the demand side didn’t go anywhere. Whoever was paying for EvilTokens still wants what EvilTokens sold, and the design pattern is now public: take a known auth abuse, add an AI layer that handles the thinking, sell access monthly. Someone is already rebuilding it.

The industry has spent years arguing about whether AI tools actually make people more productive. This case answers it in the least satisfying way possible. The tooling works. It just found its best customers first.

🕒 Published:

📊
Written by Jake Chen

AI technology analyst covering agent platforms since 2021. Tested 40+ agent frameworks. Regular contributor to AI industry publications.

Learn more →
Browse Topics: Advanced AI Agents | Advanced Techniques | AI Agent Basics | AI Agent Tools | AI Agent Tutorials
Scroll to Top