Log in Download Integrations Articles News Pricing FAQ Contact
Русский Қазақша 中文
Microsoft Shuts Down AI Agent Hacking Platform

Ars Technica · September 23, 2026 · 1Cifer

Microsoft Shuts Down AI Agent Hacking Platform

Microsoft has taken down EvilTokens, a platform that used AI to automate mass account takeovers, exposing roughly 12,000 accounts. The service worked as an all-in-one kit: it tested stolen passwords, bypassed security checks, and handed attackers ready access, with AI speeding up every step.

Previously, running an attack at this scale required a skilled team and time to assemble the right tools. EvilTokens removed that barrier, turning account theft into an almost automatic pipeline available even to people without deep technical knowledge — meaning businesses can now expect more such attacks, not fewer.

Check whether two-factor authentication is enabled everywhere your team logs in — email, CRM, banking portals, and any service running AI agents. It's also worth reviewing active sessions and access tokens, since stolen tokens are exactly what platforms like this exploit. Role-based access and a protected data perimeter are the foundation for AI agents in 1Cifer: every employee only sees the data and processes tied to their position.

Related stories

Claude Helped Researchers Hack OpenAI's SystemsHow to tell if your AI platform accounts have been hacked — and why they're hackers' new targetBiometrics at mobile operators: new subscriber protection rules and what they mean for companies

Reading us regularly? Add 1Cifer to your preferred sources in Google — our stories will show up in your news feed more often.

Add in Google

All news →