Microsoft’s EvilTokens Takedown Sheds Light on State of AI-Powered Cybercrime
- On Tuesday, Microsoft and industry partners disrupted EvilTokens, an AI-enabled phishing service linked to 12,000 compromised email inboxes across more than 10,000 organizations globally.
- EvilTokens utilized an AI-style chatbot to analyze victims' inboxes and identify sensitive details, allowing cybercriminals to bypass multi-factor authentication to silently authenticate as victims.
- Late last week, Microsoft seized 50 websites used to operate the service, while London's Metropolitan Police Service arrested two men, aged 32 and 38, who allegedly acted as administrators.
- Coinbase traced about $1.1 million in revenue for EvilTokens from paying customers, while Microsoft correlated at least 13 complaints representing approximately $1.7 million in reported losses.
- Experts advise organizations to treat unsolicited device codes as a red flag, assuming that once an inbox is compromised, criminals may understand its contents in minutes, not days.
24 Articles
24 Articles
Microsoft disrupts AI-assisted platform that compromised 12,000
EvilTokens provided an end-to-end platform that makes mass compromises faster and easier.
Microsoft and UK Police Dismantle EvilTokens Phishing Service That Compromised 12,000 Accounts
UK police arrested two suspected administrators of EvilTokens, a phishing service that compromised over 12,000 Microsoft 365 accounts at more than 10,000 organizations. Microsoft seized 50 sites and disabled 150+ domains in a multi-partner operation that highlighted the platform's AI-driven sophistication and device-code MFA bypass.
Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud
The popular phishing-as-a-service platform used AI throughout the attack chain, allowing cybercriminals to steal tokens for account takeover and business email compromise.
UK cops arrest 2 EvilTokens suspects, Microsoft seizes 50 phishing kit websites
Used by crims to compromise 12K+ email inboxes across 10K+ global orgs
Microsoft’s EvilTokens takedown sheds light on state of AI-powered cybercrime
Microsoft has hailed its success in disrupting EvilTokens, an AI-powered a phishing-as-a-service (PhaaS) platform linked to more than 12,000 compromised Microsoft 365 inboxes across more than 10,000 organizations worldwide. Since February 2026, EvilTokens has offered a subscription platform combining account compromise, mailbox analysis, target selection, and fraud preparation. Its dashboard and chatbot centralized access to those capabilities, …
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium















