EGEGazette
Live
China's Xi Jinping Travels to US for State Visit, Summit With TrumpZelensky to Address UN General Assembly as Kyiv Reports Deadly Russian StrikesTrump vows to the United Nations to resolve the Iranian file if negotiations failReport: Military aircraft crashes near US air base in Spangdahlem, GermanyReport: Spangdahlem: Military aircraft crashes near US air baseReport: F-16 fighter jet crashes near Spangdahlem US airbase in western Germany — airbaseHouthi forces push for strategic high ground in Yemen as more residents fleeVessel Struck in Strait of Hormuz Following Iranian Guard Threats, Two Lightly InjuredIran Says It Shot Down US Drone Over Strait of HormuzIran's Guard Corps Says It Downed Another US Drone Over Strait of HormuzIran says it shot down another US drone over Strait of HormuzIsraeli Drone Strike Kills Two Palestinians in Southern Gaza Despite Ceasefire
technologyReported

Microsoft Disrupts AI-Assisted Hacking Platform Linked to 12,000 Account Compromises

The company says the service, known as EvilTokens, offered an end-to-end platform that made mass account takeovers faster and easier for attackers.

· 2 min read · language: en
Article image
Ars Technica

Microsoft says it has disrupted an AI-assisted hacking platform that was used to compromise roughly 12,000 accounts, describing the service as an end-to-end tool that simplified large-scale account takeovers for attackers.

The platform, identified as EvilTokens, reportedly provided users with a streamlined way to conduct mass account compromises, according to Microsoft. The company characterized the service as notable for integrating AI-assisted capabilities that made the process faster and more accessible than earlier hacking tools.

How the Platform Operated

Details about the platform's exact technical methods were not fully outlined in the available information, though Microsoft's characterization suggests the service automated significant portions of the account-compromise process, reducing the technical expertise needed by individual attackers to carry out large-scale intrusions.

Microsoft's disruption effort targeted the infrastructure behind EvilTokens, though the company did not specify in the available details how many individuals or groups were affected by the takedown, or what legal actions, if any, have been pursued against operators of the platform.

The case adds to a growing list of AI-assisted cybercrime tools that technology companies have moved to disrupt in recent years, as generative and automated AI tools have increasingly been adapted by attackers to scale operations that previously required more manual effort.

Microsoft has periodically published findings on such disruptions as part of its broader digital crimes and threat intelligence efforts. It was not immediately clear whether affected account holders have been notified individually or what remediation steps, if any, are being offered to those whose accounts were compromised.

Sources

EGazette summarizes reporting from multiple sources; follow the links for the originals.

Related articles

Comments

Sign in to join the conversation.

Forgot password?

No account?

Loading comments…