You've been taught to be wary of fake pages. The ones that imitate your bank's website, with an odd address and a slightly blurry logo.
This scam didn't send you to a fake page. It sent you to the real one.
It was called EvilTokens. It was used to hack more than 12,000 mailboxes across more than 10,000 organisations, and France is among the countries where it claimed the most victims. Microsoft has just dismantled it.
The trap, step by step
It all began with an ordinary e-mail. A shared document, a message to review, an invoice awaiting payment.
By clicking, the victim landed on a page that gave them a code, and invited them to enter it on Microsoft's official login site. The real one. With the right address, the right padlock, nothing suspicious.
Except that by typing in that code, the victim wasn't logging in themselves. Without knowing it, they were authorising the scammer's device to enter their mailbox. A bit like a stranger asking you to go down to your building's front desk yourself to activate a badge... which is actually theirs.
No password was stolen. And that's the most worrying detail: changing your password wasn't always enough to get the scammer out, as long as their access hadn't been explicitly cut off.
What the AI did
According to Microsoft, artificial intelligence was involved at every stage. It wrote tailored e-mails, adapted to each target, so that they would look credible.
But it was once inside the mailbox that it became formidable. An assistant analysed the victim's messages: who works with whom, who trusts whom, which conversations mention payments. According to Microsoft, it helped the scammers decide who to target, who to impersonate, and how to exploit a relationship to extract as much money as possible.
Until now, this reconnaissance work took time and expertise. Only the most skilled scammers knew how to do it. EvilTokens made it available to anyone.
EvilTokens was not the work of a lone hacker, but a commercial service sold on the Telegram messaging app since February 2026. You had to pay $1,500 to get in, then $500 a month, like a subscription. Customers could choose from 44 templates of booby-trapped e-mails, and even a support service to learn how to comb through stolen mailboxes. According to Microsoft, the platform itself is said to have been programmed with the help of AI.
How it ended
With the authorisation of a US court, Microsoft and its partners seized 50 sites that ran the service and shut down more than 150 other related addresses. In London, police arrested two men aged 32 and 38, suspected of being linked to the operation. They were released pending the investigation.
For Microsoft, EvilTokens is above all a warning: what happens when criminals combine stolen access with an AI capable of understanding how an organisation works.
How not to get caught out
Never enter a code you did not ask for. That is the golden rule. If an email asks you to enter a code to open a document, stop. A genuine service never works that way.
An official page proves nothing. This trap shows that you can be made to do something foolish on the real site. What matters is not where you are, but why you went there.
If in doubt, cut everything off. If you think you have been caught out, change your password, but above all request the sign-out of every device connected to your account, or alert the IT department straight away if it is a work account. We have set out the other steps to take in our guide to dealing with a leak.
Email scams have always existed. What has changed is that they can now read your messages better than your colleagues can. So the best defence remains the simplest: take ten seconds before typing in a code.