Microsoft's Digital Crimes Unit, in tandem with an international coalition of technology companies and law enforcement agencies, has successfully disrupted EvilTokens, an AI-powered phishing-as-a-service network . The operation shut down operational domains, dismantled server backbones, and led to police arrests in the United Kingdom .

Since emerging in early 2026, the illicit platform provided cybercriminals with automated artificial intelligence tools to trick victims into entering authentication codes, compromise Microsoft 365 accounts, and conduct large-scale business email compromise campaigns .

Microsoft EvilTokens Phishing Service Disruption Marks Major Win Against Cybercrime

The coordinated action against EvilTokens represents a significant milestone in combating AI-assisted cybercrime. Operating on a commercial subscription model, EvilTokens allowed non-technical threat actors to run sophisticated financial fraud campaigns . By targeting the device code authentication flow, the service bypassed traditional security measures and affected more than 12,000 corporate inboxes across 10,000 organizations worldwide . The global coalition stripped the platform of its core server infrastructure and online presence, severing the access cybercriminals maintained over compromised accounts .

Microsoft Disrupts Cybercrime Network Targeting 12,000 Inboxes

The scale of the EvilTokens enterprise highlighted the growing industrialization of identity theft and credential abuse. Rather than stealing passwords directly, the service specialized in abusing OAuth 2.0 device authorization flows . Unwary users were prompted to enter valid device authentication codes on legitimate login pages, unwittingly granting persistent session tokens to remote threat actors .

According to telemetry from Microsoft Threat Intelligence, which tracked the primary operators under the identifier Storm-2992, the platform victimized organizations across wholesale distribution, construction, financial services, healthcare, and higher education . Concentrations of victim activity were recorded in the United States, Canada, the United Kingdom, Australia, India, and France . The wide footprint triggered joint response efforts across the tech and cybersecurity sectors.

How EvilTokens Used AI Chatbots to Automate Email Exploits

Unlike conventional phishing tools that focus solely on initial access, EvilTokens distinguished itself by embedding artificial intelligence throughout the entire exploitation lifecycle . Customers paying the service fee, marketed via Telegram for a $1,500 initiation fee and a $500 monthly subscription, received prebuilt templates alongside an integrated AI assistant .

Once access to a victim inbox was established, the AI assistant systematically scanned email histories, categorized corporate hierarchies, mapped executive relationships through Microsoft Graph queries, and surfaced pending financial transactions . The automated system then generated highly contextualized social engineering responses, crafting tailored messages that convincingly mimicked trusted colleagues or vendors to authorize fraudulent wire transfers .

Highlighting the advanced nature of the threat, Steven Masada, Associate General Counsel and General Manager at Microsoft's Digital Crimes Unit, observed during the announcement:

"While EvilTokens helped cybercriminals access email accounts, at the center of the service was an AI-style chatbot that could analyze a victim's inbox and help criminals identify trusted relationships, payment authorizations, and sensitive responsibilities, as well as other circumstances where fraud was most likely to succeed."

This operational reliance on artificial intelligence reflects broader industry trends, where advanced automation is leveraged across productivity and enterprise environments. Similar focus on AI security is evident across major tech ecosystems, such as when Microsoft patched critical Azure AI Foundry and Copilot vulnerabilities to safeguard infrastructure against autonomous exploitation.

Seizure of Domains and Law Enforcement Action

The operational takedown relied on authorization from the U.S. District Court for the Eastern District of Virginia . Microsoft collaborated with Health-ISAC and a broad industry coalition, including Cloudflare, OpenAI, Coinbase, Railway, SpyCloud, TRM Labs, and the Shadowserver Foundation . Cloudflare executed a technical purge of malicious Cloudflare Workers hosting the platform's logic , while court orders allowed the seizure of 50 core operating websites and the sinkholing of more than 150 related infrastructure domains .

Simultaneously, law enforcement intervened on the ground. The Metropolitan Police Service's Cybercrime Team in London arrested two men, aged 32 and 38, suspected of operating the platform on charges related to fraud and money laundering . Detective Inspector Serena D'Adamo noted that phishing services bring widespread harm by taking funds from everyday people and businesses, underscoring the importance of removing these platforms .

The collaborative effort demonstrates how private industry and law enforcement must combine technical countermeasures and legal frameworks to tackle threat networks. Public interest in AI governance continues to build, as reflected when the Microsoft AI chief urged industry guardrails as the White House resists regulation to mitigate similar emerging risks.

Key Security Takeaways and Guidance for Affected Organizations

The EvilTokens takedown reveals crucial lessons for corporate defense strategies, particularly regarding session management. Because token theft bypasses standard multi-factor authentication (MFA) prompts, password resets alone are insufficient to evict intruders . Security teams must explicitly revoke active refresh tokens and user sessions in Entra ID when responding to potential compromises .

Organizations are encouraged to implement strict conditional access policies, limit OAuth application permissions, restrict device code flow usage to intended hardware scenarios, and monitor mailbox rule creations that cybercriminals deploy to hide exfiltrated communications . Furthermore, ensuring that system monitoring tools are functioning correctly is critical; recently, Microsoft fixed a bug triggering false antivirus turned off alerts in Windows 11, helping administrators maintain visibility without administrative noise.

The successful disruption of EvilTokens marks a decisive step against automated phishing kits, proving that coordinated cross-industry action can successfully dismantle sophisticated cybercrime networks.