Microsoft-Led Operation Disrupts AI-Powered EvilTokens Phishing Service, Two Arrested in UK
Microsoft and partners disrupted EvilTokens, an AI-powered phishing service that hit over 12,000 inboxes, and UK police arrested two men.
Microsoft's security blog said EvilTokens used automated attacks and prebuilt phishing templates to compromise business accounts at scale. Its AI tools helped tailor lures and analyze compromised inboxes to identify high-value targets and engineer more effective phishing messages. The platform could summarize and translate emails, surface financial conversations, map organizational roles, identify trusted relationships, and recommend potential targets, Microsoft said. Preset prompts were offered to find wire-transfer discussions, locate an organization's “money movers” and vendor invoices, and determine the best people to impersonate.
EvilTokens was sold through Telegram for a $1,500 initiation fee and a recurring $500 subscription. It combined account compromise, mailbox analysis, target selection, and fraud preparation in a single service, making capabilities that once required experience across identity attacks, cloud systems, social engineering, and financial fraud available through a ready-made interface. Investigators found evidence that large portions of EvilTokens had been “vibe coded,” with AI helping its creators build the platform itself, and determined that it drew on capabilities from multiple AI models. The service included subscription pricing, customer support, management dashboards, and tools designed to move customers from account access toward financial exploitation.
To disrupt EvilTokens, Microsoft worked with Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, the Shadowserver Foundation, TRM Labs, and Health-ISAC, a nonprofit that helps health-sector organizations share cyber threat information. SpyCloud told The Hacker News that “Fifty sites seized and 150 domains disabled in a single action is only possible when the hosting providers, the exchanges, the model providers and the data holders all move at the same time.” Microsoft's Digital Crimes Unit facilitated a coordinated disruption of the infrastructure used to operate the service, Microsoft said.
Microsoft also notified affected customers, helped remediate compromised accounts, and shared intelligence to support further defensive and investigative action. It worked closely with specialist officers from the Metropolitan Police Service's cybercrime team, sharing intelligence that enabled officers to take operational action in the United Kingdom. On Sept. 11, 2026, officers arrested two men, aged 32 and 38, and seized digital devices and other items for examination, according to Microsoft. While EvilTokens used AI to identify targets and prioritize fraud opportunities, Microsoft investigators used reverse engineering and AI-powered tools to analyze evidence, accelerate the investigation, and identify the infrastructure supporting the service, the company said.
Campaigns leveraging EvilTokens have affected organizations in wholesale distribution, construction, financial services, real estate, higher education, and healthcare, with the highest concentrations of observed victim activity in the United States, Canada, the United Kingdom, Australia, India, and France, Microsoft said. In some cases, stolen tokens were used to give new devices access to a victim's inbox. A code authenticating the new device was sent to the targeted user, who unknowingly authorized the threat actor's session and granted access to the account, according to Microsoft.
Another Microsoft blog post said AI was not simply helping attackers write more convincing messages. “It helped them decide who to target, who to impersonate, and how to most effectively exploit the relationship to extract as much money as possible,” the post said. Microsoft described EvilTokens as an early warning of what happens when cybercriminals combine stolen access with AI capable of understanding how an organization works.