{
  "id": 9500241,
  "title": "Microsoft removes ‘AI chatbot’ that hacked 12,000-plus emails in 10,000 firms globally",
  "url": "https://urgent.news/2026/09/23/microsoft-removes-ai-chatbot-that-hacked-12-000-plus-emails-in-10-000",
  "topic": "ai",
  "section": "AI",
  "published": "2026-09-23T15:44:06.000Z",
  "source": {
    "name": "Times of India",
    "slug": "times-of-india",
    "url": "https://timesofindia.indiatimes.com/technology/tech-news/microsoft-says-it-has-taken-down-ai-chatbot-built-for-cybercrime-that-hacked-12000-plus-emails-across-over-10000-organisations-globally/articleshow/134441482.cms"
  },
  "original_language": "en",
  "account": "Microsoft has announced the dismantling of a subscription-based scam platform that utilized an AI chatbot to compromise over 12,000 Microsoft accounts across more than 10,000 firms worldwide. The platform, known as EvilTokens, began operating on a Telegram channel in February, charging users a $1,500 initial fee and a $500 monthly fee. The service streamlined the process of hacking email accounts at scale, identifying potential targets, impersonating trusted contacts, and drafting convincing emails to trick individuals into transferring funds. EvilTokens employed an AI-style chatbot that analyzed victims' inboxes, pinpointing relationships, payment authority, sensitive roles, and other potential vulnerabilities. The platform operated through a legitimate OAuth authentication process called device code authentication, automating the process of generating device codes for attackers to gain unauthorized access. Microsoft seized 50 websites and disabled 150 additional domains related to the scam, leading to the arrest of two men in the UK for suspected involvement. The attack marked a significant shift in the tactics used for mass account compromises, with AI playing a crucial role in identifying and exploiting vulnerabilities.",
  "summary": "Microsoft has made significant strides by taking down EvilTokens, a dangerous subscription service that exploited over 12,000 accounts via advanced AI tools. By automating hacking tasks and generating realistic phishing messages from victims' emails, the platform posed a substantial threat. Following the incident, UK authorities apprehended two individuals tied to the scheme, with Microsoft…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}