Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

EvilTokens Phishing Service Disrupted: A Glimpse into the Dark World of AI-Enabled Cybercrime


EvilTokens, a notorious Microsoft device-code phishing kit, has been disrupted by a coalition of law enforcement and private-sector tech companies, led by Microsoft. The service, which used AI to analyze victim's inboxes and provide targeted phishing campaigns, has been seized and 50 websites taken down. This marks a significant victory in the fight against cybercrime, highlighting the importance of collaboration and cooperation in the battle against AI-enabled cybercrime.

  • The notorious Microsoft device-code phishing kit, EvilTokens, has been disrupted by a coalition of law enforcement and private-sector tech companies, led by Microsoft.
  • EvilTokens, launched in February, was used by criminals to compromise 12,000 email inboxes across over 10,000 organizations worldwide.
  • The service featured an AI chatbot that analyzed a victim's inbox to identify targets, impersonate trusted contacts, and choose fraudulent strategies.
  • The disruption of EvilTokens was a result of a long-standing investigation by the Microsoft Digital Crimes Unit, working closely with law enforcement agencies and private-sector tech companies.
  • The action marks a significant milestone in Microsoft's efforts to combat cybercrime, targeting an end-to-end AI-enabled cybercrime service.
  • The disruption highlights the importance of collaboration, cooperation, and increased awareness and education about cybercrime.



  • The world of cybercrime has long been plagued by the nefarious activities of phishing services, which have become an increasingly sophisticated and insidious threat to global organizations. Recently, a notorious Microsoft device-code phishing kit known as EvilTokens has been disrupted by a coalition of law enforcement and private-sector tech companies, led by Microsoft. In a coordinated effort that spanned the US and UK, Microsoft seized 50 websites used to operate the service and disabled more than 150 additional domains tied to its supporting infrastructure. This action marks a significant milestone in the Microsoft Digital Crimes Unit's (DCU) efforts to combat cybercrime, as it is their first action against an end-to-end AI-enabled cybercrime service.

    EvilTokens was a phishing subscription that emerged in February, and within months of launching, had been used by criminals to compromise 12,000 email inboxes across more than 10,000 organizations worldwide. The service was sold as-a-service, allowing buyers to bypass multi-factor authentication (MFA) and silently authenticate as the victim to the organization's Microsoft 365 applications. What made EvilTokens especially insidious, however, was its use of AI. The service featured an AI chatbot that could analyze a victim's inbox, and help criminals identify who to target, which trusted contacts to impersonate, and even which fraud strategies to use to maximize criminals' paydays.

    The use of AI in EvilTokens was a game-changer in the world of phishing services. By leveraging machine learning algorithms, the AI chatbot could analyze vast amounts of data and provide criminals with highly targeted and personalized phishing campaigns. This made it increasingly difficult for organizations to defend against the attacks, as the AI-powered chatbot could learn and adapt to evade detection.

    The disruption of EvilTokens was a result of a long-standing investigation by the Microsoft Digital Crimes Unit, which has been working closely with law enforcement agencies to identify and disrupt cybercrime services. The investigation involved a coalition of private-sector tech companies, including Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs. Together, they worked with Microsoft to take down the EvilTokens platform and notify affected customers, helping them remediate compromised accounts.

    The impact of the disruption of EvilTokens cannot be overstated. According to Microsoft, the service had been used by criminals to compromise 12,000 email inboxes across more than 10,000 organizations worldwide. This highlights the scale of the problem and the need for organizations to take proactive steps to defend against phishing attacks.

    In a statement, Microsoft's associate general counsel and DCU GM, Steven Masada, said, "The infrastructure supporting EvilTokens has been disrupted, but the model it demonstrated will not disappear with it." He went on to emphasize the importance of strong identity protections and monitoring, as well as the need for organizations to independently verify requests to change payment information, redirect funds, or approve unusual transactions through a trusted second channel.

    The disruption of EvilTokens is a significant victory for law enforcement and private-sector tech companies working together to combat cybercrime. It highlights the importance of collaboration and cooperation in the fight against cybercrime, and serves as a reminder that organizations must take proactive steps to defend against phishing attacks.

    In a broader sense, the disruption of EvilTokens is also a reminder of the need for increased awareness and education about cybercrime. As the use of AI and machine learning becomes increasingly prevalent in the world of cybercrime, it is essential that organizations and individuals take steps to protect themselves against these types of threats.

    In conclusion, the disruption of EvilTokens is a significant milestone in the fight against cybercrime. It highlights the importance of collaboration and cooperation between law enforcement and private-sector tech companies, and serves as a reminder of the need for organizations to take proactive steps to defend against phishing attacks.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/EvilTokens-Phishing-Service-Disrupted-A-Glimpse-into-the-Dark-World-of-AI-Enabled-Cybercrime-ehn.shtml

  • https://www.theregister.com/security/2026/09/22/uk-cops-arrest-2-eviltokens-suspects-microsoft-seizes-50-phishing-kit-websites/5298317

  • https://securityshelf.com/2026/09/22/uk-cops-arrest-2-eviltokens-suspects-microsoft-seizes-50-phishing-kit-websites/


  • Published: Tue Sep 22 10:43:40 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us