Technology

A $500-a-month chatbot read victims’ inboxes and wrote the scam for them. Microsoft found 12,000 accounts hit

EvilTokens was sold on Telegram as a complete service: break into a mailbox, let AI work out who matters in it, then impersonate them convincingly. More than 10,000 organisations across six countries were affected.

A $500-a-month chatbot read victims’ inboxes and wrote the scam for them. Microsoft found 12,000 accounts hit

Microsoft says it has identified cyberattacks on more than 12,000 Microsoft accounts used by over 10,000 organisations, carried out over several months through an AI chatbot on a platform called EvilTokens.

What made it different

Plenty of criminal services send phishing mail. This one did the thinking. After quietly getting into an account, the chatbot read the victim's inbox — identifying who the important contacts were, what the relationships looked like, and which of them could be exploited. Only then did it help write the fraudulent messages, in the voice of someone the recipient already trusted.

Microsoft's account is that AI was not used merely to compose the text. It was used to decide who to target, to build the false identities, and to work out how to use the victim's existing relationships. That is the part that should worry people: the labour-intensive step in a business email compromise has always been the research, and this automated it.

It was a product, with a price list

EvilTokens first surfaced on a Telegram channel in February. Access cost $1,500 up front and $500 a month thereafter. Microsoft describes it as an integrated service covering the whole chain, from breaking into a mailbox through to extracting money by deception.

Organisations in the United States, Canada, the United Kingdom, Australia, India and France were hit hardest.

What it means in Bangladesh

Bangladesh is not on that list, and the reason is almost certainly economics rather than safety: the operators went where invoice values are highest. Nothing about the toolkit is region-specific, and the pricing puts it within reach of anyone already running local fraud.

The attack also defeats the advice most Bangladeshi offices still give. "Check the spelling", "look for odd English", "be suspicious of urgent requests" — all of that assumes the attacker is a stranger guessing. Here the message comes from a real colleague's real account, refers to a real ongoing transaction, and reads perfectly, because the system read the thread first.

Three defences work regardless of how good the writing is. Turn on multi-factor authentication everywhere, because the entire chain starts with one mailbox opening. Make a rule that any change to bank details or payment instructions is confirmed by phone on a number from your own records, never a number in the email, and apply it to the managing director as firmly as to anyone else — the whole point of this tooling is to impersonate seniority. And check your Microsoft 365 or Google Workspace admin console for mail-forwarding rules and connected apps you did not create, which is how access outlives a password change.

This is the same shift we described when AI-generated "pity scam" videos made emotional fraud cost nothing to produce, and it sits alongside the breach of enterprise cloud software earlier this week: the expensive parts of attacking people are being automated one at a time.

Source: প্রথম আলো

Written by

Tech BD

Editorial team of Tech BD.