Microsoft and Partners Dismantle AI-Powered EvilTokens Phishing Platform

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Microsoft, Coinbase, and law enforcement dismantled EvilTokens, an AI-driven phishing service that compromised 12,000 Microsoft accounts across 10,000 organizations. The platform used AI chatbots to analyze inboxes, identify targets, and automate fraud, leading to financial harm. Two suspects were arrested in the UK, and $1.1 million in illicit revenue was traced.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event involves an AI system (EvilTokens) used maliciously to conduct phishing attacks that have directly caused harm to individuals and organizations through fraud and unauthorized access to email accounts. The AI's role in analyzing inboxes and automating attack strategies is central to the harm caused. Therefore, this qualifies as an AI Incident due to realized harm stemming from the AI system's use in cybercrime.[AI generated]
AI principles
Privacy & data governanceRobustness & digital security

Industries
Digital security

Affected stakeholders
Business

Harm types
Economic/PropertyHuman or fundamental rights

AI system task:
Interaction support/chatbotsContent generation


Articles about this incident or hazard