Microsoft disrupts AI-assisted platform EvilTokens that compromised 12,000 accounts
Summarized by AI from reporting by Ars Technica AI, published under our editorial policy.
Microsoft's Digital Crimes Unit took down EvilTokens, an AI-powered platform that automated mass account compromises and breached at least 12,000 accounts across various services.

Key takeaways
- Microsoft's Digital Crimes Unit disrupted EvilTokens, an AI-powered hacking platform that compromised at least 12,000 accounts.
- EvilTokens provided an end-to-end platform that automated the hacking process, making mass compromises easier for attackers.
- The disruption involved taking down servers, blocking malicious domains, and collaborating with other cybersecurity firms.
- Users are advised to use strong, unique passwords and enable multi-factor authentication to protect their accounts.
Microsoft has disrupted EvilTokens, an AI-powered platform that enabled mass compromises of user accounts. The platform automated various hacking processes, making it significantly easier for attackers to breach accounts on a large scale. EvilTokens was responsible for compromising at least 12,000 accounts before Microsoft intervened.
What EvilTokens actually did
EvilTokens provided an end-to-end platform that automated the process of compromising user accounts. The platform used AI to streamline various stages of the hacking process, from identifying vulnerable accounts to executing the breaches. This automation made it possible for even relatively inexperienced attackers to carry out large-scale compromises with minimal effort. Microsoft's investigation revealed that the platform was used to breach at least 12,000 accounts across various services.
How Microsoft disrupted the platform
Microsoft's Digital Crimes Unit (DCU) worked to dismantle the infrastructure behind EvilTokens. The disruption involved taking down servers, blocking malicious domains, and collaborating with other cybersecurity firms to mitigate the threat. Microsoft also shared information with affected users, advising them on steps to secure their accounts. The company emphasized the importance of using strong, unique passwords and enabling multi-factor authentication to protect against such attacks.
Why the rise of AI-powered hacking matters
The takedown of EvilTokens highlights the growing role of AI in cybercrime. As AI technologies become more accessible, they are increasingly being exploited by malicious actors to automate and scale their attacks. For everyday users, this means that the threat landscape is evolving, and traditional security measures may no longer be sufficient. It's crucial for individuals to stay informed about the latest security practices and to take proactive steps to protect their online accounts.
Steps to protect your accounts from similar threats
To safeguard your accounts from similar threats, you can take several immediate steps. First, ensure that you use strong, unique passwords for each of your online accounts. Password managers can help generate and store these passwords securely. Second, enable multi-factor authentication (MFA) wherever possible. MFA adds an extra layer of security by requiring a second form of verification, such as a text message or authentication app, in addition to your password. Finally, regularly review your account activity for any suspicious logins or transactions. If you notice anything unusual, change your password immediately and report the incident to the service provider.
Frequently asked
- What was EvilTokens?
- EvilTokens was an AI-powered platform that automated the process of compromising user accounts, making it easier for attackers to carry out mass breaches.
- How many accounts were compromised by EvilTokens?
- At least 12,000 accounts were compromised by EvilTokens before Microsoft disrupted the platform.
- What steps can I take to protect my accounts from similar threats?
- Use strong, unique passwords, enable multi-factor authentication, and regularly review your account activity for any suspicious logins or transactions.