EvilTokens Takedown Nets Two Arrests in UK
Microsoft-led coalition seizes 50 phishing sites and disables 150 domains tied to an AI-enabled service that compromised 12,000 inboxes.
Two men in London are out on bail after police alleged they ran the administrative backbone of EvilTokens, a device-code phishing service that let criminals bypass multi-factor authentication and sign in as victims to Microsoft 365 applications. The arrests came on September 18, as a coalition led by Microsoft moved against the service's web presence and supporting domains.
The operation, coordinated across the US and UK, seized 50 websites used to operate EvilTokens and disabled more than 150 additional domains tied to its infrastructure, according to Microsoft. The company said the kit, which first appeared in February, was used to compromise 12,000 email inboxes across more than 10,000 organizations worldwide.
A kit built for repeat abuse
EvilTokens operated as a phishing subscription, sold as-a-service to buyers who wanted access to corporate inboxes without triggering the usual authentication alarms. The core technique was device-code phishing, a flow that asks a user to enter a code on a legitimate Microsoft sign-in page. Because the user authenticates on Microsoft's own domain, the method slips past MFA prompts that would otherwise stop a password-based attack.
What distinguished EvilTokens from the crowded market for phishing kits was its use of an AI chatbot. Microsoft said the tool could analyze a victim's inbox and help criminals decide who to target, which trusted contacts to impersonate, and which fraud strategies to pursue. That combination — valid session tokens plus automated reconnaissance — moved the service beyond simple credential theft into something closer to a turnkey intrusion platform.
Microsoft's disclosure that EvilTokens was AI-enabled is notable for what it says about the economics of phishing-as-a-service. Buyers did not need to write convincing lures or manually sift through a stolen mailbox. The kit handled the analysis and suggested the next move, lowering the skill floor for launching targeted business email compromise campaigns.
What Microsoft observed before the takedown
In an earlier interview with The Register, Microsoft VP of security research Tanmay Ganacharya described the volume of activity tied to the service. "Since March 15, 2026, we have observed 10 to 15 distinct campaigns launching every 24 hours," Ganacharya said.
That figure — 10 to 15 campaigns per day, observed from mid-March 2026 — captures the pace at which EvilTokens buyers put the kit to work. The service had been live since February, meaning the campaign volume Ganacharya described began roughly a month after it appeared.
Microsoft said the takedown, carried out with authorizations from the US District Court for the Eastern District of Virginia, involved working with Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation and TRM Labs. The company also notified affected customers and helped them remediate compromised accounts.
The arrests and the police statement
London's Metropolitan Police Service arrested two men, aged 32 and 38, on September 18. Both were released on bail while the investigation continues. The Met alleged the men acted as administrators of the EvilTokens website.
Detective Inspector Serena D'Adamo, whose team led the Met's investigation, described the wider impact of such services in an emailed statement to The Register. "Phishing services bring misery to thousands, taking money from everyday people across the world," D'Adamo said. "The Met remains committed to holding people to account who facilitate criminal enabling functions and think they can remain undetected."
The involvement of Health-ISAC, a nonprofit that helps health sector organizations share cyber-threat information, added a sector-specific plaintiff to Microsoft's legal action. Healthcare organizations were among those targeted by EvilTokens users, and Health-ISAC joined as a co-plaintiff.
Scale of the affected population
The numbers Microsoft released outline a service that reached well beyond a handful of victims. According to the company's account, EvilTokens was used to compromise 12,000 email inboxes across more than 10,000 organizations worldwide. The takedown covered 50 seized websites and more than 150 disabled domains tied to supporting infrastructure.
- 12,000 email inboxes compromised, according to Microsoft
- 10,000+ organizations affected worldwide
- 50 websites seized in the disruption
- 150+ additional domains disabled
- 10 to 15 campaigns observed every 24 hours since March 15, 2026
- 40th court-authorized disruption by Microsoft's Digital Crimes Unit over nearly two decades
The operation was not the Digital Crimes Unit's first, but Microsoft described it as a milestone of a different kind. Steven Masada, associate general counsel and DCU GM, said in a blog shared with The Register ahead of publication that this was the unit's first action against an end-to-end AI-enabled cybercrime service.
The AI angle that set it apart
Most phishing kits in circulation are variations on familiar themes: cloned login pages, credential-harvesting forms, or reverse-proxy setups that capture session cookies. EvilTokens sat in the device-code category, but the AI chatbot layered on top changed what a buyer could do after gaining access to a mailbox.
Microsoft's description of the tool's capabilities — analyzing a victim's inbox, identifying targets, selecting contacts to impersonate, and recommending fraud strategies — points to a service designed around the post-compromise phase, not just the initial credential capture. That is the part of a business email compromise operation that typically requires human judgment and time.
The company's public messaging after the takedown focused on that shift. Masada framed the disruption as a temporary win against a durable model rather than a permanent fix.
"The infrastructure supporting EvilTokens has been disrupted, but the model it demonstrated will not disappear with it," he said in a blog shared with The Register ahead of publication. "For organizations, the lesson is: assume that once an inbox is compromised, criminals may understand its contents in minutes, not days. Strong identity protections and monitoring remain essential, but organizations should also independently verify requests to change payment information, redirect funds or approve unusual transactions through a trusted second channel."
— Steven Masada, associate general counsel and DCU GM at Microsoft
The broader coalition behind the action
The list of partners Microsoft named reads like a cross-section of the infrastructure and financial plumbing that phishing services depend on. Cloudflare, a major provider of DNS and web security services, appeared alongside Railway, an application hosting platform. OpenAI participated, as did SpyCloud and The Shadowserver Foundation, both of which work in threat intelligence and internet measurement.
Coinbase and TRM Labs, two firms whose work centers on cryptocurrency, rounded out the group. Their presence in the operation reflects the role that digital-asset tracing can play in mapping the financial side of criminal services, though Microsoft's announcement did not detail how their contributions were used.
The legal mechanism was a court order from the US District Court for the Eastern District of Virginia, which authorized Microsoft and Health-ISAC to act against the infrastructure. That procedural step — obtaining a judge's authorization before seizing domains — is the model Microsoft's Digital Crimes Unit has used across its 40 disruptions over nearly two decades.
What Microsoft is telling customers
Beyond the seizures and arrests, Microsoft said it notified affected customers and helped them remediate compromised accounts. That remediation focus matters because a compromised mailbox rarely stays contained: with valid session tokens, an attacker can read email, send messages as the user, and reach connected services. Organizations that receive a notification should treat it as a signal to review sign-in logs, revoke active sessions, and check for mail-forwarding rules or other persistence mechanisms.
Masada's guidance emphasized a second layer of defense beyond identity controls: independent verification of payment and transaction requests through a separate channel. That advice targets the fraud that tends to follow inbox compromise — payment redirection, invoice fraud, and approval requests that appear to come from a known colleague.
Microsoft's numbers suggest the reach of the service was substantial, with more than 10,000 organizations affected. For security teams, the operational takeaway from the company's own framing is that detection windows may be short: if an attacker can understand an inbox's contents quickly, the gap between compromise and fraudulent request may be measured in minutes.
Why the takedown matters beyond the arrests
The disruption removes one piece of infrastructure, but the service model it represents is the more durable problem. Phishing-as-a-service lowers the barrier to entry by packaging technical capability behind a subscription, and EvilTokens added AI-assisted analysis on top of that. Even with 50 sites seized and 150-plus domains disabled, the underlying technique — device-code phishing that sidesteps MFA — does not depend on any single domain.
For businesses, the practical implication is that MFA alone may not stop this class of attack. Device-code flows are legitimate parts of the Microsoft ecosystem, which is exactly what makes them attractive to abusers. Organizations may want to review how device-code authentication is used in their environments, monitor for suspicious sign-ins that use it, and treat any inbox compromise as a potential precursor to payment fraud.
For consumers, the arrests and seizures are a reminder that phishing services operate as businesses with administrators, infrastructure, and payment rails — and that those layers can be targeted by law enforcement working with private companies. The Met's statement made clear that its investigation continues, with both suspects released on bail.
For the industry, the coalition model on display here — a court order, a group of infrastructure and intelligence partners, and a coordinated seizure — is one that Microsoft has now used 40 times. Whether it translates into lasting pressure on phishing services depends on how quickly replacements emerge and how willing victims are to report incidents that feed future investigations. Masada's own assessment was that the model will persist even as this particular infrastructure comes down.
Sources
- The Register Original source
Continue Reading
Stolen Passwords Expose 1,787 Water Providers
SpyCloud research finds infostealer malware has harvested credentials tied to 1,787 U.S. water and wastewater organizations, some reaching operational networks.
Fake Job Interviews Fuel North Korea Crypto Theft
A joint advisory links WaterPlum's developer-targeting campaign to over $10.7m in stolen cryptocurrency and 30,000 infected devices worldwide.
Defender zero-day halts antivirus updates
A researcher's new Windows Defender zero-day prevents signature and platform updates, the latest in a string of exploits tied to a dispute with Microsoft.