Microsoft says it has disrupted EvilTokens, a service behind 12,000 hijacked accounts

single source· 1 articles · confidence: low · first seen 2026-09-22 19:45 UTC

What this means for you

Nothing to install or migrate. What matters is the packaging: the ability to compromise accounts in bulk was offered as a finished service rather than assembled per campaign, which lowers the skill needed to run one. This report gives no detail on what Microsoft disabled or whether the operation has stopped.

Microsoft has disrupted EvilTokens, which Ars Technica describes as an AI-assisted platform linked to 12,000 compromised accounts. The outlet says the service provided an end-to-end capability for taking over accounts at scale, making mass compromises faster and easier. The report does not say what the AI component does, who ran the platform, whether anyone has been charged, or what Microsoft's action actually disabled.

Key facts

  • ·Microsoft disrupted a platform called EvilTokens, according to Ars Technica. source
  • ·Ars Technica links the platform to 12,000 compromised accounts. source
  • ·Ars Technica describes the platform as AI-assisted. source
  • ·The outlet describes EvilTokens as an end-to-end platform that makes mass compromises faster and easier. source
  • ·The report was published on 22 September 2026. source

What the sources say

  • Ars Technica AI (press) — Reports a Microsoft takedown of a service that made bulk account compromise quicker and simpler to run.

Sources

The original reporting. Follow these — they did the work.

← the wire