3 Sources
[1]
UK Cops arrest 2 EvilTokens suspects, Microsoft seizes 50 phishing kit websites
Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks 20 days ago A coalition of law enforcement and private-sector tech companies led by Microsoft have disrupted the EvilTokens phishing service, arresting suspected website admins, taking down more than 50
[2]
A major AI-powered phishing service has lost access to its key infrastructure
Why it matters: While the AI industry panics about extinction risks that are years away, financially motivated hackers are already using existing AI tools to turn stolen corporate network access into opportunities for fraud. Driving the news: Microsoft's Digital Crimes Unit obtained authorization
[3]
Microsoft and Coinbase probe leads to arrest of crooks behind 'EvilTokens', a DIY phishing network powered by AI | Fortune
In a blog post describing the scam, the companies explained that EvilTokens sold a do-it-yourself phishing kit over Telegram designed to exploit Microsoft Outlook email accounts. The kit came with a sinister feature, described by the post as "an AI-powered analyst that mapped trusted relationships,
Share
Copy Link
Microsoft's Digital Crimes Unit seized 50 websites tied to EvilTokens, a notorious AI-powered phishing service that compromised 12,000 email inboxes across 10,000 organizations. UK police arrested two men suspected of running the operation, which generated $1.1 million by enabling cybercriminals to bypass two-factor authentication and conduct sophisticated fraud.

Microsoft led a coalition of law enforcement agencies and private-sector tech companies to disrupt EvilTokens, an AI-powered phishing service that compromised more than 12,000 email inboxes across 10,000 organizations worldwide
1
2
. The Microsoft Digital Crimes Unit obtained authorization from the U.S. District Court for the Eastern District of Virginia to seize 50 websites used to operate the EvilTokens phishing service and disabled more than 150 additional domains tied to its supporting infrastructure1
. London's Metropolitan Police Service arrested two men, aged 32 and 38, on September 18 on suspicion of making articles for use in fraud and money laundering offenses3
. Both suspects have been released on bail while the investigation continues.EvilTokens emerged in February and quickly gained traction among cybercriminals as a subscription-based phishing kit sold on Telegram
3
. The service charged hackers a $1,500 initiation fee and $500 per month for access, with some reports indicating monthly costs between $100 and $3002
3
. What made this AI-enabled cybercrime service particularly dangerous was its ability to bypass multi-factor authentication and silently authenticate as victims to their organization's Microsoft 365 applications1
. The phishing kit used device-code phishing tactics, tricking victims into entering codes on legitimate Microsoft sign-in pages that unknowingly granted hackers access to their accounts2
. Since March 15, 2026, Microsoft observed 10 to 15 distinct campaigns launching every 24 hours1
.The EvilTokens phishing service featured an AI chatbot that could analyze a victim's inbox and help cybercriminals identify who to target, which trusted contacts to impersonate, and which fraud strategies to use
1
. This AI-powered analyst mapped trusted relationships, identified who controlled payments, and flagged where fraud was most likely to succeed3
. The AI condensed work that could otherwise take hackers several days into hours, helping them determine who controlled the money, whom they trusted, and whom to impersonate2
. Charlotte Surrey, an investigator on Coinbase's global intelligence team, noted that the tool "completely obliterates the barrier to entry on phishing as a service, and can be operated on an industrial scale"3
. Microsoft also found evidence that large portions of EvilTokens were "vibe coded," or built using AI tools themselves, underscoring how AI was used on both sides of the cybercrime operation2
.Investigators determined the perpetrators collected approximately $1.1 million between October 2025 and June 2026
3
. The money was paid in cryptocurrency to wallets on the Tron blockchain and came from over 700 distinct addresses3
. Coinbase, one of the companies that helped Microsoft on the investigation, traced this revenue to the platform2
. Microsoft observed the highest concentrations of victim activity in the U.S., Canada, the UK, Australia, India, and France, with targeted organizations spanning construction, financial services, real estate, higher education, and healthcare sectors2
. Because healthcare organizations were among those targeted, Health-ISAC joined Microsoft's legal action as a co-plaintiff1
.Related Stories
The operation marked the Microsoft Digital Crimes Unit's 40th court-authorized disruption over nearly two decades and its first action against an end-to-end AI-enabled cybercrime service
1
. Microsoft worked with Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs to execute the takedown1
. The investigation began as a collaboration between Microsoft and Coinbase, with security teams regularly swapping intelligence on cyber threats3
. A Microsoft spokesperson told Axios that the company started publicly warning customers about EvilTokens' tactics in April and moved quickly once the scale and sophistication of the threat became clear2
.Steven Masada, associate general counsel and general manager in Microsoft's Digital Crimes Unit, warned that while the infrastructure supporting EvilTokens has been disrupted, the model it demonstrated will not disappear
1
. He emphasized that organizations should assume that once an inbox is compromised, criminals may understand its contents in minutes, not days1
. According to Coinbase, at the time of the takedown, the EvilTokens perpetrators were working on newer phishing tools to target Okta and Gmail accounts3
. This development represents a concerning evolution where AI models help malicious hackers scale and speed up attacks while lowering the barrier for less-sophisticated hackers to enter cybercrime2
. Organizations need to independently verify requests to change payment information, redirect funds, or approve unusual transactions through a trusted second channel, alongside maintaining strong identity protections and monitoring1
.Summarized by
Navi
14 Jan 2026•Policy and Regulation

12 Jun 2026•Technology

16 Apr 2025•Technology

1
Technology

2
Science and Research

3
Technology
