Microsoft Disrupts AI-Powered EvilTokens Service Linked to 12,000 Hacked Inboxes
Microsoft disrupts AI-powered EvilTokens phishing service, impacting 12,000 inboxes.
Summary
Microsoft has taken down EvilTokens, an AI-powered phishing-as-a-service platform that compromised over 12,000 email inboxes across 10,000 organizations. The service used AI to analyze compromised inboxes, identify payment authorization capabilities, and map trusted relationships to facilitate complex financial fraud. The operation involved seizing 50 websites and disabling over 150 domains, with two arrests made in the UK.
Full text
Cyber Crime Phishing ScamMicrosoft Disrupts AI-Powered EvilTokens Service Linked to 12,000 Hacked Inboxes Microsoft disrupted EvilTokens after the AI-powered phishing service compromised 12,000 inboxes across 10,000 organisations and enabled complex financial fraud. byWaqasSeptember 23, 20263 minute read Listen to this article 0:00 — ← 10s ▶ Play 10s → Speed 0.75× 1× 1.25× 1.5× 2× Voice Loading voices… Press play to start listening Microsoft has disrupted EvilTokens, an AI-powered phishing-as-a-service platform linked to the compromise of more than 12,000 email inboxes across over 10,000 organisations worldwide since February 2026. The coordinated operation resulted in the seizure of 50 websites used to operate EvilTokens and the disabling of more than 150 additional domains supporting the service. Authorities also arrested two men in the United Kingdom in connection with the alleged operation. According to Microsoft’s Digital Crimes Unit, the operation was authorised by the US District Court for the Eastern District of Virginia. Health-ISAC also joined Microsoft’s legal case as a co-plaintiff because healthcare organisations were among the targets. Microsoft worked with Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, the Shadowserver Foundation and TRM Labs to identify and disable infrastructure supporting EvilTokens. The company also contacted affected customers and helped them secure compromised accounts. EvilTokens’ infrastructure Two Men Arrested in the UK Officers from the Metropolitan Police cybercrime team arrested two men, aged 32 and 38, on September 11, 2026. Police seized digital devices and other items for examination. Police later released both suspects on conditional bail while the investigation continued. Neither man has been convicted, and Microsoft did not disclose their identities or alleged roles in the service. Microsoft tracks the threat actor responsible for developing and supporting EvilTokens as Storm-2992. The service was advertised through Telegram for an initial fee of $1,500, followed by a $500 monthly subscription. Customers received phishing templates, hosting options, redirect tools, token-management features and technical support. EvilTokens’ seizure notice EvilTokens Used AI After Accounts Were Compromised Microsoft said EvilTokens used AI for more than generating convincing phishing messages. Its chatbot could analyse compromised inboxes, identify employees authorised to make payments and map trusted relationships between victims, executives and outside organisations. The system could search for invoices, wire-transfer discussions and executive correspondence before recommending who criminals should impersonate and how they could carry out financial fraud. Investigators also found indications that large parts of the EvilTokens platform itself had been developed with assistance from multiple AI models. According to the company, EvilTokens abused Microsoft’s device-code authentication flow, a legitimate sign-in method intended for devices such as smart televisions, printers and conference-room equipment. The platform allowed attackers to generate a device code and trick victims into entering it on Microsoft’s legitimate sign-in page. Those who completed the authentication process, including multifactor authentication when required, unknowingly authorised a session controlled by the attacker. The stolen tokens could then provide mailbox access without revealing the victim’s password. Operators used malicious inbox rules, device registration and token-refresh mechanisms to maintain access and conceal communications. Previous EvilTokens Campaigns Hackread.com previously reported how EvilTokens was used with Outlook calendar invitations to place phishing messages directly into users’ schedules. The invitations remained visible even when the original emails were moved to junk or deleted. A separate EvilTokens campaign exposed a visibility gap for enterprise security teams, as parts of the attack occurred through legitimate browser-based authentication and cloud services rather than traditional malware. Microsoft observed the highest levels of EvilTokens activity in the United States, Canada, the United Kingdom, Australia, India and France. Affected organisations operated in financial services, construction, healthcare, higher education, real estate and wholesale distribution. The company recommends blocking device-code authentication where it is unnecessary. Organisations that require it should restrict access through Conditional Access policies, monitor unusual device registrations and Microsoft Graph activity, and revoke compromised tokens rather than relying on password resets alone. Waqas I am a UK-based cybersecurity journalist with a passion for covering the latest happenings in cybersecurity and tech world. I am also into gaming, reading and investigative journalism. View Posts Cyber CrimeCybersecurityEvilTokensFraudMicrosoftPhishingUnited Kingdom Leave a Reply Cancel reply View Comments (0) Related Posts Read More Cyber Crime Hackers hit hackers in new malware campaign It seems odd but a malware campaign is circulating on the web for the past few years where the prime targets are no one else but hackers. byDeeba Ahmed Read More Cyber Crime Security Data Breach Index Website “Leakbase” Shut Down On December 2nd, Leakbase.pw, a data breach index website announced it has closed down the service effective immediately.… byWaqas Read More Cyber Crime Netherlands Busts Bulletproof Hosting Network Linked to Disinformation and Cybercrime Dutch authorities arrested two suspects after dismantling a bulletproof hosting network linked to cybercrime, disinfo, and Russian sanctions evasion. byWaqas Read More Cyber Crime Phishing Scam Security Google Docs Phishing Scam Cost Minnesota State Thousands of Dollars Last Wednesday the Internet was full of news reports regarding a new sophisticated phishing scam using Google Docs to… byWaqas