Microsoft Dismantles EvilTokens Phishing Service That Compromised 12,000 Email Accounts
A coalition of law enforcement and private-sector partners led by Microsoft has disrupted the EvilTokens phishing service, which compromised over 12,000 inboxes at more than 10,000 organizations. The service, launched in February 2026, gave criminals access to email accounts along with an AI chatbot that analyzed what they found inside.
Victims were tricked into entering an authentication code on Microsoft's legitimate sign-in page, unknowingly handing over access without revealing their passwords. Once inside a mailbox, the service's AI tools could summarize and translate emails, surface financial conversations, map roles within the organization, and identify trusted relationships.
The platform also offered preset prompts to find wire transfer discussions, locate vendor invoices, identify the organization's 'money movers,' and determine who to impersonate. Microsoft observed the highest concentrations of victim activity in the US, Canada, the UK, Australia, India, and France.
Microsoft, along with partners Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs, seized 50 websites used to operate the service and disabled over 150 domains tied to its infrastructure. On September 11, 2026, officers from the Metropolitan Police Service's cybercrime team arrested two men suspected of operating EvilTokens.
Steven Masada, Associate General Counsel and GM of Microsoft's Digital Crimes Unit, noted that no single organization could disrupt EvilTokens alone, as it relied on various online resources repurposed to support fraud at scale. He advised organizations to assume that once an inbox is compromised, criminals 'may understand its contents in minutes'.