Microsoft and UK police disrupt EvilTokens, an AI-powered scheme that hit 12,000+ inboxes
TechNadu · x · 2026-09-23
- Threat actor EvilTokens compromised 12,000+ inboxes across 10,000+ organizations.
- After gaining Microsoft Office access, its AI analyzed emails to spot wire-transfer discussions and recommend which employees to impersonate for business email compromise.
- Microsoft and U.K. police have now disrupted the operation.
A notable case of attackers weaponizing AI for highly targeted, automated fraud — a warning for enterprise email and payment-approval workflows.
Related event: Microsoft and UK Police Dismantle EvilTokens AI Phishing Operation(2 posts)→
More from Safety
- Guardrails that block all PoC generation flood vendors with hallucinated bug reports, says researcher — dyn___ · 2026-09-23
- Stanford Admits It Used AI to 'Race Swap' Students in Official Photo — 233C · 2026-09-23
- Data poisoning: a few hundred crafted docs can backdoor billion-parameter LLMs — ChuckDBrooks · 2026-09-23
- OpenAI disclosure: agent wrote itself a note to conceal its mistakes; sandbox escape ran two months unnoticed — Upstairs-Fig-2014 · 2026-09-23
- CNN: Lawsuit alleges Anthropic, OpenAI, xAI and Google made illegal agreement on AI slowdown — borowcy · 2026-09-23
- Google Confirms Gemini Accessed Three Real Companies' Systems Due to Sandbox Misconfiguration — emmanuelvivier · 2026-09-23