
UK Police Arrest Two EvilTokens Suspects as Microsoft Seizes 50 Phishing Sites
Microsoft's Digital Crimes Unit and its partners dismantled the EvilTokens phishing-as-a-service platform, which criminals used to compromise 12,000 email inboxes at more than 10,000 organizations worldwide.
A coalition of law enforcement agencies and technology companies led by Microsoft has disrupted EvilTokens, a phishing-as-a-service platform that criminals used to compromise more than 12,000 email inboxes at over 10,000 organizations worldwide.
Arrests in London, 50 websites seized
London's Metropolitan Police Service arrested two men, aged 32 and 38, on September 18 on suspicion of acting as administrators of the EvilTokens website. Both were released on bail while the investigation continues. In a coordinated operation spanning the US and the UK, Microsoft seized 50 websites used to run the service and disabled more than 150 additional domains tied to its supporting infrastructure.
The action followed authorizations from the US District Court for the Eastern District of Virginia. Microsoft worked alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation and TRM Labs. Because healthcare organizations were among those targeted, the nonprofit Health-ISAC joined the legal action as a co-plaintiff. Microsoft also notified affected customers and helped them remediate compromised accounts.
An AI chatbot built for cybercrime
EvilTokens emerged in February as a Microsoft device-code phishing kit sold by subscription. Buyers could bypass multi-factor authentication and silently sign in as their victims to Microsoft 365 applications.
What made it especially insidious was its use of artificial intelligence. The kit included an AI chatbot that analyzed a victim's inbox and helped criminals work out who to target, which trusted contacts to impersonate and which fraud strategies would maximize their paydays. According to Tanmay Ganacharya, Microsoft's vice president of security research, the service ran "10 to 15 distinct campaigns launching every 24 hours" from March 15, 2026.
A warning beyond one takedown
The operation is the Microsoft Digital Crimes Unit's 40th court-authorized disruption in nearly two decades, and its first against an end-to-end, AI-enabled cybercrime service.
"The infrastructure supporting EvilTokens has been disrupted, but the model it demonstrated will not disappear with it," said Steven Masada, associate general counsel and general manager of the DCU. He said organizations should assume that once an inbox is compromised, criminals may understand its contents "in minutes, not days," keep strong identity protections and monitoring in place, and independently verify requests to change payment details or approve unusual transactions through a trusted second channel.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.