Microsoft-led takedown disrupts EvilTokens, an AI-powered phishing service tied to 12,000 hacked inboxes
Two men aged 32 and 38 were arrested in the UK and released on bail, after a US court order let Microsoft and its partners seize 50 websites.

Evidence: Independent reports. Security stories run only with a named disclosure or independent reporting behind them.
Microsoft's Digital Crimes Unit led the disruption of EvilTokens, a phishing-as-a-service platform. Investigators link it to more than 12,000 compromised Microsoft accounts at more than 10,000 organizations. EvilTokens appeared in February. BleepingComputer says it was the first such service to support device-code authentication phishing at scale. It used AI to customize lures, sift through breached inboxes for high-value targets and plan fraud. The Record reports that the platform was sold on Telegram for a $1,500 initiation fee plus $500 a month. According to CyberScoop, a federal court order issued September 15 let Microsoft and its partners seize 50 websites and disable more than 175 supporting domains. A Microsoft spokesperson said about 1,000 criminals used the service. Health-ISAC, law enforcement and SpyCloud took part. The UK's Metropolitan Police arrested two men, aged 32 and 38, who are suspected of running the service. Both were released on bail. Microsoft tracks the operators as Storm-2992 and says others may have supported the service. The case shows how quickly AI tools are being packaged for sale to low-skill fraudsters.
Sources
- BleepingComputerEvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts
- The RecordTwo arrested in UK after Microsoft takedown of ‘Eviltokens’ AI-chatbot for cybercriminals
- CyberScoopMicrosoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud
- The Hacker NewsMicrosoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises