AI News Feed
Market watch
Cybersecurity

Microsoft and UK Police Arrest Two, Seize 200 Domains in Takedown of AI-Powered EvilTokens Phishing Service

Microsoft joined UK police and industry partners to disrupt EvilTokens, an AI-assisted phishing-as-a-service platform that compromised more than 12,000 inboxes at over 10,000 organizations worldwide.

According to TechRadar, the Metropolitan Police's cybercrime team arrested two men, aged 32 and 38, on suspicion of offenses connected with the alleged operation of EvilTokens. Their identities were not disclosed. Both have been released on bail with conditions while the investigation continues, and their digital services and other items were confiscated. The operation seized 50 websites and disabled 150 domains, according to Microsoft's account of the joint action.

Microsoft listed its partners in the operation as Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation and TRM Labs. Whether the arrests and seizures will end EvilTokens' operations entirely remains unclear; criminal infrastructure generally withstands disruption less well when arrests follow than when law enforcement only disables hardware.

EvilTokens was first spotted in February 2026 and quickly became one of the most widely used phishing platforms. It was sold through Telegram for $1,500, followed by a recurring $500 subscription. Buyers could build spoofed websites and landing pages, generate tailored phishing emails, and capture session tokens, one-time passwords and other codes meant to protect accounts, giving attackers access to victims' mailboxes.

The platform shipped with an AI assistant that sorted through inboxes, flagged high-value targets and suggested how to approach them, and it supported Microsoft Graph reconnaissance to map organizational structure and permissions, hold access and move laterally through a target network. Microsoft said it found evidence that large portions of EvilTokens had been vibe coded, with AI helping its creators build the platform itself, and that the service drew on capabilities from multiple AI models. Described as running like an organized startup, it offered subscription pricing, customer support, management dashboards and tools that moved customers from account access toward financial exploitation.

Microsoft said EvilTokens enabled business email compromise campaigns that compromised more than 12,000 inboxes across more than 10,000 organizations worldwide. Victims were concentrated in wholesale distribution, construction and financial services, with real estate, higher education and healthcare also affected. Most victims were in the United States, with significant numbers in Canada, the United Kingdom, Australia, India and France. Microsoft said it notified affected customers, helped remediate compromised accounts and shared intelligence to support further defensive and investigative work.

Device-code phishing predates EvilTokens. Huntress reported in February 2025 that the Russian threat actor Storm-2372 used the technique, and its popularity grew steadily until the platform's arrival. In June 2026 the same researchers said EvilTokens had driven a 1,380 percent increase in device-code phishing attacks in 2026 compared with the same period a year earlier. Huntress said its telemetry showed that rise between July-December 2025 and January-April 2026, with more than half of the incidents linked to two major correlated waves.