---
title: "Microsoft Takes Down EvilTokens AI Phishing Service"
date: 2026-09-22
author: "Sofia Ramirez"
featured_image: "https://sqmagazine.co.uk/wp-content/uploads/2026/09/microsoft-takes-down-eviltokens-ai-phishing-service.jpg"
categories:
  - name: "Cybersecurity"
    url: "/cybersecurity.md"
tags:
  - name: "News"
    url: "/tag/news.md"
---

# Microsoft Takes Down EvilTokens AI Phishing Service

Microsoft said on September 22, 2026 that it disrupted EvilTokens, a subscription cybercrime service whose AI chatbot read stolen inboxes and chose which colleagues to defraud. None of its victims handed over a password.

## What to Know?

- Microsoft linked EvilTokens to more than 12,000 compromised email inboxes across over 10,000 organizations within months of its February 2026 launch.
- The service sold access for a $1,500 initiation fee plus a $500 recurring subscription, advertised through a Telegram storefront.
- Victims authenticated on Microsoft’s real sign-in page, so operators took mailbox access without ever seeing a password.
- Microsoft and Health-ISAC filed jointly in a Virginia federal court, acting alongside Cloudflare, Coinbase, OpenAI, and other partners.
- Metropolitan Police officers arrested two men in the United Kingdom and seized digital devices for examination.

## How It Happened?

EvilTokens tricked targets into entering an authentication code on Microsoft’s own sign-in page. The victim completed a normal login. The criminal collected the resulting session, and no credential ever crossed the wire.

That access could persist even after a password reset if the associated sessions and tokens were not also revoked, Microsoft said. Any team that rotated credentials after a suspected [phishing email incident](https://sqmagazine.co.uk/phishing-email-statistics/) and stopped there may still have a reader in the mailbox today.

> Since emerging in February 2026, EvilTokens quickly became one of the most widely used phishing-as-a-service (PhaaS) platforms, enabling sophisticated device code phishing campaigns aimed at compromising organizational accounts at scale. <https://t.co/p1o6QHSLKP>
> 
> — Microsoft Threat Intelligence (@MsftSecIntel) [September 22, 2026](https://x.com/MsftSecIntel/status/2102416154039865510?ref_src=twsrc%5Etfw)

 ## The Chatbot That Picked the Targets

Once inside an account, EvilTokens ran an AI assistant across the contents. It summarized and translated messages, surfaced financial conversations, mapped organizational roles, and flagged trusted relationships worth impersonating. Preset prompts offered to find wire-transfer discussions, identify an organization’s “**money movers**,” locate vendor invoices, and name the best people to impersonate.

Microsoft put the shift plainly in its [announcement](https://blogs.microsoft.com/on-the-issues/2026/09/22/disrupting-eviltokens-the-ai-chatbot-built-for-cybercrime/):

“

AI was not simply helping attackers write more convincing messages. It helped them decide who to target, who to impersonate, and how to most effectively exploit the relationship to extract as much money as possible.

Microsoft





Investigators also found that large portions of the platform had been “**vibe coded**,” with AI helping its creators build the service, and that EvilTokens drew on capabilities from multiple AI models. Microsoft has not said which models. The published account also does not quantify how much money the chatbot’s recommendations actually moved, how many of the 12,000 inboxes were queried, or how long the average intruder stayed.

## Who Was Hit and Who Took It Down?

Victim activity concentrated in the United States, Canada, the United Kingdom, Australia, India, and France. Affected organizations ran from wholesale distribution and construction through financial services, real estate, higher education, and healthcare.

Working with partners, Microsoft seized **50** websites used to operate the service and disabled more than 150 additional domains tied to its supporting infrastructure, with authorization from the U.S. District Court for the Eastern District of Virginia. Health-ISAC, a global nonprofit that helps health sector organizations share cyber threat intelligence, joined as co-plaintiff because healthcare bodies were among the targets. Cloudflare, [Coinbase](https://sqmagazine.co.uk/coinbase-statistics/), OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs acted against separate parts of the platform.

Metropolitan Police cybercrime officers arrested two men, aged 32 and 38, on September 11, 2026, seizing digital devices and other items. Both were released on police bail subject to conditions while the investigation continues. Microsoft counts the case as the Digital Crimes Unit’s 40th court-authorized disruption and its first against an **[end-to-end AI-enabled cybercrime service](https://sqmagazine.co.uk/generative-ai-cybersecurity-threats/)**.

## Why It Matters?

Most inbox-compromise playbooks assume an attacker needs days to learn a company well enough to steal from it. EvilTokens shrank that window to the length of a chatbot query, which is why the old advice to watch for a slow, clumsy impersonation attempt no longer fits the threat. Strong identity policy helps reduce the risk of the first compromise, though it does not prevent one.

What is next: the two arrested men remain under investigation on bail, and Microsoft is still notifying affected customers and sharing intelligence with partners. Security teams should read the Microsoft Threat Intelligence write-up on device-code attacks, then revoke active sessions and refresh tokens rather than resetting passwords alone. Reviewing [credential and password hygiene](https://sqmagazine.co.uk/password-statistics/) helps, though it does nothing about a token already stolen. Verify every request to change payment details or redirect funds through a second trusted channel.