Skip to content
Unlisted Report logoUnlisted ReportSubscribe
News

Microsoft takes down EvilTokens AI phishing service

The platform used an AI chatbot to plan fraud from 12,000+ hacked inboxes. Microsoft seized 50 sites and UK police arrested two men.

By · Published · Updated · 4 min read

Microsoft takes down EvilTokens AI phishing service

Microsoft and partners have disrupted EvilTokens, a phishing service that used AI to help criminals pick victims and plan fraud, Microsoft says.

What EvilTokens did

  • Sold on Telegram for a $1,500 joining fee and $500 a month, The Record reports.
  • Stole login tokens for Microsoft 365, bypassing multi-factor authentication.
  • Its AI chatbot read victims' inboxes, spotted trusted relationships and payment approvals, and drafted messages impersonating trusted contacts.

Since launching in February 2026, it was linked to more than 12,000 compromised inboxes at over 10,000 organizations. About 1,000 criminals used it.

The takedown

  • Under a court order, Microsoft seized 50 websites and disabled more than 150 related domains.
  • Cloudflare removed the attackers' infrastructure from its network.
  • London's Metropolitan Police arrested two men, aged 32 and 38, on suspicion of fraud and money laundering offences.

Why it matters

AI is no longer just writing better phishing emails. Here it decided who to target and how to steal the most money — a sign of where business email fraud is heading.

How to protect your organization

  • Use phishing-resistant sign-in such as passkeys or security keys.
  • Require a phone call to a known number before changing payment details.
  • Review mailbox rules and sign-in alerts for unusual activity.

Sources

Read next