Microsoft disrupts EvilTokens phishing service that gave criminals access to 12,000 inboxes
Microsoft and partners seized EvilTokens infrastructure after the phishing service compromised over 12,000 inboxes.
Microsoft, with court authorization and partners including Health-ISAC, Cloudflare, Coinbase, and OpenAI, disrupted the EvilTokens phishing service, which compromised more than 12,000 inboxes at over 10,000 organizations. Victims entered an authentication code on Microsoft's legitimate sign-in page, granting persistent token access that could survive a password reset. The service's AI tools summarized and translated mail, identified payment contacts, and drafted impersonation messages. It sold on Telegram for a $1,500 fee plus $500 recurring. On September 11, 2026, London police arrested two men, and Microsoft seized 50 sites and disabled more than 150 domains.