UK Police Detain Two After Microsoft Shuts Down ‘EvilTokens’ AI Crime Service
British authorities have taken two suspects into custody following the removal of the "EvilTokens" chatbot from Microsoft’s platform. The service, which operated on Telegram, marketed itself to cyber‑offenders for a $1,500 entry fee and a recurring $500 subscription, offering artificial‑intelligence‑driven tools designed to breach accounts, sift through compromised email boxes and suggest the most profitable ways to exploit stolen data.
Microsoft acted after receiving multiple abuse reports that linked the chatbot to a surge in credential‑theft incidents across Europe. The company’s takedown request cited violations of its terms of service and the broader risk the tool posed to its users. Once the service was disabled, law‑enforcement agencies coordinated a swift investigation that led to the arrests.
The two individuals detained are alleged to have managed the chatbot’s infrastructure and handled payments from subscribers. While their identities have not been released, officials confirmed that the suspects used anonymising services and cryptocurrency wallets to conceal transactions, a common practice among operators of underground cyber‑crime markets.
"EvilTokens" represented a new frontier in criminal‑as‑a‑service, leveraging advanced language models to automate many steps that previously required manual expertise. According to the police, the AI could parse large volumes of stolen emails, identify high‑value credentials, and even draft phishing messages tailored to specific targets, dramatically lowering the technical barrier for less‑skilled attackers.
Cyber‑security experts say the episode underscores the dual‑use dilemma of generative AI. While the technology promises productivity gains, it can also be weaponised to streamline illicit activities. "We are seeing a rapid commoditisation of hacking tools powered by AI," noted a researcher at a leading security firm. "Platforms that host communication channels, like Telegram, are increasingly becoming vectors for these services, and the challenge for providers is to detect and act on abuse before it scales."p>
Law‑makers in the UK have been urging tighter regulation of AI‑enabled services, especially those that facilitate crime. The recent arrests may add momentum to pending legislative proposals that would require companies to monitor and report suspicious AI applications. However, critics argue that overly broad measures could stifle legitimate innovation.
Investigators continue to examine the full extent of the operation, including whether the chatbot had additional customers outside the United Kingdom. The case also raises questions about the responsibility of platform providers to police AI‑driven content and the resources needed to keep pace with rapidly evolving threats. As the legal process unfolds, authorities say they remain committed to dismantling similar services that exploit emerging technologies for criminal gain.
Comments (0)
Be the first to comment.
Join the discussion