Microsoft says it just took down a subscription service that turned business email compromise into a monthly-billed product.
The company said Tuesday it led an industry-wide takedown of EvilTokens, a platform that first surfaced on a Telegram channel in February and compromised roughly 12,000 Microsoft accounts within a few months. Access cost $1,500 upfront, plus $500 a month after that. For the money, subscribers got an AI chatbot that scanned a hijacked inbox, flagged which contacts controlled payments or held sensitive responsibilities, and drafted follow-up messages impersonating those trusted contacts. The goal, per Microsoft, was tricking employees into wiring money to attacker-controlled accounts.
Business email compromise has always required patience: attackers used to spend days reading a victim's mail to learn who trusted whom before faking a request. EvilTokens compressed that reconnaissance into minutes and packaged it as an off-the-shelf subscription, meaning the barrier to running a convincing wire-fraud scheme dropped to whatever a criminal could afford per month.
Microsoft didn't say how much money actually moved before the shutdown - which, as usual with vendor-led takedowns, is the number that would tell you whether this actually worked.