Microsoft’s Digital Crimes Unit has dismantled EvilTokens, a phishing-as-a-service platform blamed for hijacking more than 12,000 Microsoft accounts across over 10,000 organizations. The takedown came alongside the arrest of two suspected administrators, ages 32 and 38, by London’s Metropolitan Police Service.
The operation targeted a specific attack method: device-code phishing, which tricks victims into approving a login on Microsoft’s own legitimate sign-in page while an attacker captures the resulting access token, bypassing multi-factor authentication without ever stealing a password. EvilTokens had been running since February 2026, building a subscriber base of criminal customers rather than operating as a single group carrying out its own attacks.
An AI Chatbot Built Into the Phishing Kit
What set EvilTokens apart from older phishing kits was software built to do the sorting work after a break-in. Microsoft’s own account of the disruption describes an AI chatbot that could analyze a victim’s inbox, and help criminals identify who to target, which trusted contacts to impersonate, and even which fraud strategies to use to maximize criminals’ paydays. Rather than a customer buying stolen credentials and figuring out what to do with them, EvilTokens’ subscribers got a tool that read the compromised mailbox for them and recommended a next move.
Microsoft’s Digital Crimes Unit called the case its first action against what it termed an end-to-end AI-enabled cybercrime service, and its 40th court-authorized disruption overall. The company’s separate security blog post on the technical side of the takedown describes the underlying attack as one that stolen tokens are used for email exfiltration and persistence, often through inbox rules, meaning attackers set up hidden mail-forwarding rules that kept letting them read a victim’s email long after the initial token was captured.
Two Arrests and Dozens of Seized Websites
Detective Inspector Serena D’Adamo of the Metropolitan Police Service led the UK investigation that resulted in the September 18 arrests. Officers took the two suspects into custody at addresses in Canary Wharf and Nine Elms; both were released on bail pending further investigation. Alongside the arrests, Microsoft seized 50 websites tied to the phishing-kit infrastructure and disabled more than 150 additional domains, the technical backbone that let EvilTokens’ customers launch new phishing campaigns.
Microsoft credited outside partners for making the case possible. “Working with partners, Microsoft’s Digital Crimes Unit (DCU) facilitated a coordinated disruption,” the company said in its security blog post describing the action, naming Health-ISAC, the healthcare-sector information-sharing group, and threat-intelligence firm SpyCloud among the organizations that contributed evidence and technical support to the case.
How Widespread the Damage Actually Was
SpyCloud’s own accounting of the campaign, drawn from recaptured phished data it contributed as evidence, put the number at 8,708 unique victim accounts across 6,585 corporate email domains in 79 countries, a somewhat narrower slice than Microsoft’s broader 12,000-account figure but one that shows the same pattern: 97.5 percent of the victims SpyCloud identified belonged to enterprise domains rather than personal webmail accounts, and just the top ten EvilTokens customers accounted for 60 percent of all victims the firm tracked.
That concentration matters for how the takedown was built. Rather than chasing thousands of individual criminals renting the service, investigators appear to have focused on identifying the platform’s operators and its highest-volume customers, the accounts responsible for the bulk of the damage even within a subscriber base that was, by Microsoft’s count, spread across more than 10,000 victim organizations.
What Microsoft Is Telling Account Holders Now
Microsoft’s guidance for anyone who might have been targeted centers on the specific mechanism EvilTokens exploited: verifying which application is actually requesting a sign-in before approving a device code, since the attack works because that approval screen looks identical whether the request is legitimate or not. The company is also pointing organizations toward phishing-resistant authentication methods, including FIDO2 security keys and passkeys, which cannot be phished the way a one-time code or an approval tap can.
Device-code phishing itself is not new, but EvilTokens’ operators, per BleepingComputer’s reporting on the case, had built a platform capable of compromising accounts at a scale that drew Microsoft’s Digital Crimes Unit into a formal legal action, rather than the smaller, harder-to-track campaigns that have typically used the technique since it first emerged as a known abuse pattern.
The court-authorized action that let Microsoft seize EvilTokens’ domains follows a legal playbook the company’s Digital Crimes Unit has used against dozens of criminal infrastructure operations before, but the unit’s own framing of this case as its first against an AI-enabled service suggests investigators expect the pairing of phishing kits with automated victim analysis to keep showing up in whatever comes after EvilTokens. Two arrests and a round of seized domains slow one operation down; they do not by themselves retire the underlying technique or the AI tooling built around it.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- A recalled pill hid a stimulant dose linked to heart attacks and death
- Four U.S. startups fired up their first small nuclear reactors, aiming to power AI data centers on-site
- Card skimmers hidden on gas pumps and ATMs are draining accounts, and here’s the tell
- Doctors warn a silent liver disease now affects one in three American adults