Microsoft's Digital Crimes Unit seized 50 websites tied to EvilTokens, a notorious AI-powered phishing service that compromised 12,000 email inboxes across 10,000 organizations. UK police arrested two men suspected of running the operation, which generated $1.1 million by enabling cybercriminals to bypass two-factor authentication and conduct sophisticated fraud.

News article

Microsoft and Law Enforcement Dismantle Major AI-Enabled Cybercrime Service

Microsoft led a coalition of law enforcement agencies and private-sector tech companies to disrupt EvilTokens, an AI-powered phishing service that compromised more than 12,000 email inboxes across 10,000 organizations worldwide

1

2

. The Microsoft Digital Crimes Unit obtained authorization from the U.S. District Court for the Eastern District of Virginia to seize 50 websites used to operate the EvilTokens phishing service and disabled more than 150 additional domains tied to its supporting infrastructure

1

. London's Metropolitan Police Service arrested two men, aged 32 and 38, on September 18 on suspicion of making articles for use in fraud and money laundering offenses

3

. Both suspects have been released on bail while the investigation continues.

How the DIY Phishing Network Powered by AI Operated

EvilTokens emerged in February and quickly gained traction among cybercriminals as a subscription-based phishing kit sold on Telegram

3

. The service charged hackers a $1,500 initiation fee and $500 per month for access, with some reports indicating monthly costs between $100 and $300

2

3

. What made this AI-enabled cybercrime service particularly dangerous was its ability to bypass multi-factor authentication and silently authenticate as victims to their organization's Microsoft 365 applications

1

. The phishing kit used device-code phishing tactics, tricking victims into entering codes on legitimate Microsoft sign-in pages that unknowingly granted hackers access to their accounts

2

. Since March 15, 2026, Microsoft observed 10 to 15 distinct campaigns launching every 24 hours

1

.

AI Chatbot for Phishing Accelerated Fraud Operations

The EvilTokens phishing service featured an AI chatbot that could analyze a victim's inbox and help cybercriminals identify who to target, which trusted contacts to impersonate, and which fraud strategies to use

1

. This AI-powered analyst mapped trusted relationships, identified who controlled payments, and flagged where fraud was most likely to succeed

3

. The AI condensed work that could otherwise take hackers several days into hours, helping them determine who controlled the money, whom they trusted, and whom to impersonate

2

. Charlotte Surrey, an investigator on Coinbase's global intelligence team, noted that the tool "completely obliterates the barrier to entry on phishing as a service, and can be operated on an industrial scale"

3

. Microsoft also found evidence that large portions of EvilTokens were "vibe coded," or built using AI tools themselves, underscoring how AI was used on both sides of the cybercrime operation

2

.

Arrest of EvilTokens Suspects and Financial Impact

Investigators determined the perpetrators collected approximately $1.1 million between October 2025 and June 2026

3

. The money was paid in cryptocurrency to wallets on the Tron blockchain and came from over 700 distinct addresses

3

. Coinbase, one of the companies that helped Microsoft on the investigation, traced this revenue to the platform

2

. Microsoft observed the highest concentrations of victim activity in the U.S., Canada, the UK, Australia, India, and France, with targeted organizations spanning construction, financial services, real estate, higher education, and healthcare sectors

2

. Because healthcare organizations were among those targeted, Health-ISAC joined Microsoft's legal action as a co-plaintiff

1

.

Coordinated Takedown Involved Multiple Tech Partners

The operation marked the Microsoft Digital Crimes Unit's 40th court-authorized disruption over nearly two decades and its first action against an end-to-end AI-enabled cybercrime service

1

. Microsoft worked with Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs to execute the takedown

1

. The investigation began as a collaboration between Microsoft and Coinbase, with security teams regularly swapping intelligence on cyber threats

3

. A Microsoft spokesperson told Axios that the company started publicly warning customers about EvilTokens' tactics in April and moved quickly once the scale and sophistication of the threat became clear

2

.

Future Implications for Cybersecurity and AI-Driven Threats

Steven Masada, associate general counsel and general manager in Microsoft's Digital Crimes Unit, warned that while the infrastructure supporting EvilTokens has been disrupted, the model it demonstrated will not disappear

1

. He emphasized that organizations should assume that once an inbox is compromised, criminals may understand its contents in minutes, not days

1

. According to Coinbase, at the time of the takedown, the EvilTokens perpetrators were working on newer phishing tools to target Okta and Gmail accounts

3

. This development represents a concerning evolution where AI models help malicious hackers scale and speed up attacks while lowering the barrier for less-sophisticated hackers to enter cybercrime

2

. Organizations need to independently verify requests to change payment information, redirect funds, or approve unusual transactions through a trusted second channel, alongside maintaining strong identity protections and monitoring

1

.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved