Ars Technica · September 23, 2026 · 1Cifer
Microsoft Shuts Down AI Agent Hacking Platform
Microsoft has taken down EvilTokens, a platform that used AI to automate mass account takeovers, exposing roughly 12,000 accounts. The service worked as an all-in-one kit: it tested stolen passwords, bypassed security checks, and handed attackers ready access, with AI speeding up every step.
Previously, running an attack at this scale required a skilled team and time to assemble the right tools. EvilTokens removed that barrier, turning account theft into an almost automatic pipeline available even to people without deep technical knowledge — meaning businesses can now expect more such attacks, not fewer.
Check whether two-factor authentication is enabled everywhere your team logs in — email, CRM, banking portals, and any service running AI agents. It's also worth reviewing active sessions and access tokens, since stolen tokens are exactly what platforms like this exploit. Role-based access and a protected data perimeter are the foundation for AI agents in 1Cifer: every employee only sees the data and processes tied to their position.


