Back to all stories

Microsoft disrupts AI-powered EvilTokens phishing platform

Microsoft, alongside UK law enforcement and industry partners, has disrupted EvilTokens, an AI-powered phishing-as-a-service platform responsible for compromising 12,000 inboxes across 10,000 organizations. The operation led to the arrest of two suspects and the seizure of over 200 domains, underscoring the escalating threat of AI-driven cybercrime.

LA

LazyFounders

·4 min read
Microsoft disrupts AI-powered EvilTokens phishing platform
Image: (Image credit: Shutterstock / JLStock) via TechRadar

Microsoft, alongside UK law enforcement and industry partners, has disrupted EvilTokens, an AI-powered phishing-as-a-service platform responsible for compromising 12,000 inboxes across 10,000 organizations. The operation led to the arrest of two suspects and the seizure of over 200 domains, underscoring the escalating threat of AI-driven cybercrime.

30 SEC SUMMARY

  • Microsoft and partners disrupted the EvilTokens phishing-as-a-service (PhaaS) platform, leading to the arrest of two suspects.
  • Over 200 domains linked to EvilTokens were seized or disabled in the operation.
  • The platform compromised 12,000 inboxes across 10,000 organizations, primarily in the US.
  • EvilTokens used AI to scale device-code phishing attacks, driving a 1,380% increase in such attacks in 2026.
  • The tool was sold via Telegram for $1,500, with a $500 recurring subscription.

TABLE OF CONTENTS

  • Operation targets EvilTokens PhaaS platform
  • Impact and scope of the platform
  • AI’s role in scaling attacks
  • What this means
  • Key takeaways
  • FAQ
  • Sources

KEY HIGHLIGHTS

  • Microsoft and partners disrupted the EvilTokens phishing-as-a-service (PhaaS) platform in a global operation.
  • Two suspects were arrested in the UK and released on bail pending further investigation.
  • Over 200 domains and sites linked to EvilTokens were seized or disabled.
  • The platform compromised 12,000 inboxes across 10,000 organizations, primarily in the US.
  • EvilTokens used AI to scale device-code phishing, leading to a 1,380% increase in such attacks in 2026.

Operation targets EvilTokens PhaaS platform

According to TechRadar, Microsoft, in collaboration with the UK Metropolitan Police Service and partners like Health-ISAC, Cloudflare, and OpenAI, disrupted the EvilTokens phishing-as-a-service (PhaaS) platform. The operation led to the arrest of two suspects, aged 32 and 38, who were later released on bail pending further investigation.

The platform, which was first identified in February 2026, was sold via Telegram for $1,500, with a recurring subscription fee of $500. It enabled cybercriminals to launch large-scale phishing attacks, primarily targeting high-value industries.

Impact and scope of the platform

EvilTokens compromised more than 12,000 inboxes across 10,000 organizations worldwide, with the majority of victims located in the United States. According to TechRadar, industries such as wholesale distribution, construction, financial services, real estate, higher education, and healthcare were among the most affected.

The operation also resulted in the seizure or disabling of over 200 domains and sites linked to the platform. Microsoft and its partners targeted the infrastructure supporting EvilTokens, aiming to cripple its operations globally.

AI’s role in scaling attacks

The EvilTokens platform leveraged artificial intelligence to scale its device-code phishing attacks, a method that exploits authentication mechanisms to gain unauthorized access to accounts. According to TechRadar, this led to a 1,380% increase in such attacks in 2026 compared to the same period in 2025.

AI was reportedly used to identify and target high-value victims, automating the selection of targets and customizing phishing lures to increase success rates. This marks a significant evolution in the sophistication of phishing tools available to cybercriminals.

What this means

LazyFounders analysis — our interpretation, not reported fact.

The takedown of EvilTokens underscores the growing threat of AI-driven cybercrime and the increasing accessibility of sophisticated phishing tools. For founders and operators, this serves as a reminder of the importance of robust cybersecurity measures, particularly as attackers leverage AI to refine and scale their methods.

The collaboration between Microsoft, law enforcement, and industry partners also highlights the need for cross-sector coordination to combat cyber threats. Startups, especially those in high-target industries like financial services and healthcare, should prioritize employee training, multi-factor authentication, and threat detection systems to mitigate risks.

This case also raises questions about the future of cybercrime—and whether AI will continue to lower the barrier to entry for malicious actors. Founders should stay informed about emerging threats and consider investing in adaptive security solutions that can evolve alongside attack techniques.

Key takeaways

  • Microsoft, UK police, and partners took down the EvilTokens PhaaS platform in a coordinated operation.
  • Two suspects were arrested and released on bail, with over 200 domains seized.
  • EvilTokens targeted high-value industries, including financial services, healthcare, and construction.
  • AI played a key role in scaling the platform’s phishing attacks, leading to a surge in device-code phishing.
  • The operation highlights the growing threat of AI-driven cybercrime and the need for cross-sector collaboration.

FAQ

What was EvilTokens?

EvilTokens was a phishing-as-a-service (PhaaS) platform that provided cybercriminals with tools to launch large-scale phishing attacks. It used AI to scale device-code phishing and target high-value victims across industries.

How did EvilTokens compromise accounts?

The platform exploited device-code phishing, a technique that tricks users into authorizing access to their accounts. AI was used to automate target selection and customize phishing lures, increasing the success rate of attacks.

Who were the primary targets of EvilTokens?

EvilTokens primarily targeted organizations in the US, with victims spanning industries like wholesale distribution, construction, financial services, real estate, higher education, and healthcare.

What role did AI play in EvilTokens' attacks?

AI enabled EvilTokens to scale its attacks by automating the identification of high-value targets and customizing phishing attempts. This contributed to a 1,380% increase in device-code phishing attacks in 2026.

Why is this takedown significant for businesses?

The takedown highlights the growing sophistication of cyber threats, particularly those powered by AI. Businesses must adapt by investing in advanced security measures, employee training, and threat detection systems to protect against evolving attack methods.

Related on LazyFounders

Sources

  1. TechRadar · 2026-09-23
    Microsoft takes down AI-boosted phishing tool that hit 12,000 accounts

This story is an original summary and analysis written by LazyFounders from the reporting listed above. Facts are attributed to their original publishers; sections marked as analysis are LazyFounders's opinion. Where a source is in another language, facts were machine-translated and quotations are reported, not reproduced. Read the original coverage via the links.

Lazy Founder - Powered by Blogy.in