Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud
Court-ordered seizure of 50 EvilTokens websites disables an AI-driven PhaaS tied to 12,000 compromised Microsoft inboxes and $1.7M reported losses.
Acting on a federal court order dated September 15, Microsoft and partners seized 50 websites and disabled more than 175 domains supporting the EvilTokens phishing-as-a-service platform, which compromised over 12,000 Microsoft email inboxes across 10,000+ organizations since February 2026. About 1,000 cybercriminals used the service, which applied AI at every attack stage, from token theft to inbox analysis for BEC targeting. Microsoft correlated at least 13 FBI IC3 complaints representing roughly $1.7 million in losses, while Coinbase traced about $1.1 million in operator revenue from more than 1,000 deposits. UK Metropolitan Police arrested two suspected operators, aged 32 and 38, on September 18, both released on bail.