Microsoft has announced the takedown of EvilTokens, a cybercrime platform that utilized artificial intelligence (AI) to facilitate account compromises and financial fraud. The operation involved legal action and collaboration with several partners to dismantle the service and its infrastructure.
In conjunction with the takedown, the Metropolitan Police Service in the UK arrested two men, aged 32 and 38, earlier this month. These individuals are alleged operators of the EvilTokens platform. Both have since been released on bail as the police investigation continues.
EvilTokens operated as a subscription-based service on Telegram, requiring a $1,500 initiation fee and a $500 monthly subscription. It offered cybercriminals AI tools to compromise accounts, analyze breached inboxes, and identify methods for monetizing access through fraud. Microsoft is tracking the threat actors behind EvilTokens as Storm-2992. The service is estimated to have been tied to 12,000 inbox compromises.
The takedown was initiated through a lawsuit filed by Microsoft and Health-ISAC in U.S. District Court, which granted authorization to dismantle the platform. Key partners in this effort included Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs. Steven Masada, Microsoft Digital Crimes Unit associate general counsel, stated that the AI-style chatbot at the core of EvilTokens could analyze victim inboxes to identify trusted relationships, payment authorizations, and sensitive responsibilities, increasing the likelihood of successful fraud.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Microsoft announced the disruption of EvilTokens, an AI-powered phishing platform that compromised over 12,000 email accounts across 10,000 organizations since February 2026. The platform utilized AI for customized phishing emails and data exfiltration, and its disruption involved seizing 50 websites and disabling 150 domains, alongside the arrest of two individuals.
Microsoft led an industry-wide disruption of EvilTokens, a subscription-based scam platform that used an AI chatbot to compromise 12,000 Microsoft accounts across 10,000 organizations. The platform offered tools for email account compromise, inbox analysis, target selection, and drafting fraudulent emails, leveraging device code authentication. This disruption addresses a significant threat that automated business email compromise attacks.
Microsoft, in collaboration with several partners, has taken down the EvilTokens device code phishing service, which utilized AI to compromise email accounts and facilitate financial fraud. This action led to the arrest of two individuals and disrupted a platform responsible for an estimated 12,000 inbox compromises.
Microsoft took legal action to dismantle EvilTokens, an AI-powered cybercrime platform, leading to the arrest of two individuals in the UK. This action disrupts a service that provided cybercriminals with AI tools for account compromise and financial fraud, highlighting ongoing efforts to combat AI-enabled criminal activities.