Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

EvilTokens Phishing Service Disrupted: Microsoft and UK Cops Crack Down on AI-Driven Cybercrime


Microsoft, in collaboration with law enforcement agencies, has disrupted the EvilTokens phishing service, a notorious AI-driven cybercrime platform that had compromised the email inboxes of over 12,000 organizations across 10,000 global entities. This operation marks a significant milestone for the Microsoft Digital Crimes Unit, as it is their 40th court-authorized disruption of an illicit online service.

  • Microsoft disrupted the EvilTokens phishing service, a notorious AI-driven cybercrime platform, in collaboration with law enforcement agencies.
  • The service had compromised the email inboxes of over 12,000 organizations across 10,000 global entities.
  • The AI-driven phishing service allowed buyers to bypass multi-factor authentication and silently authenticate as a victim to Microsoft 365 applications.
  • A coordinated effort between Microsoft and law enforcement agencies led to the disruption of the service, resulting in the arrest of two men accused of being its administrators.
  • The disruption highlights the growing threat of AI-driven cybercrime and the importance of prioritizing cybersecurity and taking proactive steps to protect against phishing attacks.
  • Organizations should verify requests to change payment information or approve unusual transactions through a trusted second channel to prevent further damage.



  • Microsoft, in collaboration with law enforcement agencies, has successfully disrupted the EvilTokens phishing service, a notorious AI-driven cybercrime platform that had compromised the email inboxes of over 12,000 organizations across 10,000 global entities. This operation marks a significant milestone for the Microsoft Digital Crimes Unit, as it is their 40th court-authorized disruption of an illicit online service.

    The EvilTokens phishing service was launched in February and had quickly gained notoriety for its sophisticated AI-driven approach to phishing. The service allowed buyers to purchase a subscription to bypass multi-factor authentication and silently authenticate as a victim to Microsoft 365 applications. The AI chatbot featured on the platform could analyze a victim's inbox, identify trusted contacts, and even predict which fraud strategies to use to maximize the criminals' paydays.

    The disruption of the EvilTokens phishing service was made possible through a coordinated effort between Microsoft and law enforcement agencies. Microsoft seized 50 websites used to operate the service, disabled over 150 additional domains tied to its supporting infrastructure, and notified victims of compromised email accounts. London's Metropolitan Police Service arrested two men, aged 32 and 38, who allegedly acted as the administrators of the EvilTokens website. Both men have been released on bail while the investigation continues.

    The disruption of the EvilTokens phishing service highlights the growing threat of AI-driven cybercrime. The use of AI in phishing campaigns has become increasingly sophisticated, making it more difficult for organizations to protect themselves against these types of attacks. Microsoft's efforts to disrupt this service demonstrate the company's commitment to protecting its customers against these types of threats.

    The impact of the EvilTokens phishing service cannot be overstated. Healthcare organizations were among those targeted, highlighting the potential for significant financial and reputational damage. The disruption of this service serves as a reminder for organizations to prioritize their cybersecurity and to take proactive steps to protect themselves against phishing attacks.

    In light of this operation, Microsoft's associate general counsel and Digital Crimes Unit GM, Steven Masada, emphasized the importance of assuming that once an inbox is compromised, criminals may understand its contents in minutes, not days. Strong identity protections and monitoring remain essential, but organizations should also independently verify requests to change payment information, redirect funds, or approve unusual transactions through a trusted second channel.

    The disruption of the EvilTokens phishing service marks an important milestone in the fight against AI-driven cybercrime. As the threat landscape continues to evolve, it is essential for organizations and law enforcement agencies to work together to stay ahead of these types of threats.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/EvilTokens-Phishing-Service-Disrupted-Microsoft-and-UK-Cops-Crack-Down-on-AI-Driven-Cybercrime-ehn.shtml

  • https://www.theregister.com/security/2026/09/22/uk-cops-arrest-2-eviltokens-suspects-microsoft-seizes-50-phishing-kit-websites/5298317


  • Published: Tue Sep 22 12:43:57 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us