Microsoft's Digital Crimes Unit seized 50 sites and disrupted 150+ domains linked to EvilTokens, an AI-driven phishing platform that Microsoft says compromised more than 12,000 inboxes across 10,000+ organizations. The service—sold on Telegram—bundled AI-crafted lures, 44 email templates, and an inbox-searching chatbot to facilitate targeted account takeovers and payment fraud. Two suspects were arrested and released on bail as investigations continue. Microsoft and partners recommend blocking device-code authentication and independently verifying fund-transfer requests.
Microsoft Disrupts EvilTokens: AI-Powered Phishing Service Taken Offline after Global Takedown

Microsoft's Digital Crimes Unit has seized 50 websites and disrupted more than 150 related domains tied to EvilTokens, an AI-assisted phishing platform that Microsoft says compromised over 12,000 email inboxes at more than 10,000 organizations worldwide.
The Metropolitan Police Service's cybercrime team arrested two men, aged 32 and 38, on September 11 in connection with the platform; both have since been released on bail as investigations continue.
How EvilTokens Operated
Launched in February 2026 and marketed via Telegram, EvilTokens sold access for a $1,500 initiation fee plus a $500 monthly subscription. Buyers received a turnkey phishing toolkit that bundled 44 email templates, AI-crafted lure messages tailored to a target's role, and an inbox-searching chatbot that surfaced payment threads, identified decision-makers, flagged trusted contacts, and recommended fraud strategies.
Microsoft said the platform consolidated capabilities that once required multiple specialists—spanning identity exploitation, cloud environment misuse, social engineering, and financial fraud—into a single commercial interface.
Device-Code Phishing and Persistent Access
EvilTokens relied on device-code phishing: victims were tricked into entering an authentication code on Microsoft's legitimate sign-in page. Although passwords were not disclosed, attackers obtained access tokens that allowed full account access. That access could persist even after a password change unless sessions and tokens were explicitly invalidated.
Using the platform's AI, attackers quickly identified finance and executive personnel, extracted conversations about wire transfers and invoices, and composed realistic messages impersonating trusted contacts to redirect payments. In some incidents, attackers enrolled new devices on a compromised account within ten minutes, creating a durable foothold that could survive token revocation alone.
Scope, Impact, and Partners
Victims spanned sectors including wholesale distribution, construction, financial services, real estate, higher education, and healthcare. Incidents were most concentrated in the United States, Canada, the United Kingdom, Australia, India, and France. Axios reported that Coinbase, which participated in the wider investigation, estimated EvilTokens generated roughly $1.1 million in revenue.
Health-ISAC joined Microsoft as a co-plaintiff in civil action authorized by the U.S. District Court for the Eastern District of Virginia. Other partners in the disruption included Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs. Microsoft described this as its 40th court-authorized disruption and its first against a fully end-to-end AI-enabled cybercrime service.
Warnings and Recommendations
Microsoft and partners noted that device-code phishing is a recurring and evolving threat; the FBI previously warned about a similar service, Kali365, which abused Microsoft’s device-code authentication flow to capture tokens and bypass multifactor authentication without stealing passwords.
To reduce exposure, Microsoft recommends blocking device-code authentication where feasible by using Conditional Access policies in Microsoft Entra ID, and independently verifying any requests to redirect funds or change payment information through a separate, trusted channel.
Bottom line: The disruption of EvilTokens highlights how AI can be used to automate complex fraud workflows and underscores the need for tighter authentication controls and independent validation of financial requests.
Help us improve.



























