Skip to main content
    All AI News
    IT ProWednesday, September 23, 2026 2 min read
    AI

    Microsoft Takes Down 'EvilTokens' Cybercrime Service

    AI-powered PhaaS platforms now automate target selection and fraud strategy—not just phishing email drafts.

    Key takeaways
    • 01Microsoft's takedown of EvilTokens exposes a new tier of criminal capability: AI that scanned compromised inboxes to rank victims by fraud potential, recommended impersonation tactics, and drafted contextually aware lures.
    • 02The platform compromised over 12,000 inboxes across 10,000+ organizations in roughly seven months.
    • 03Fifty operational sites and 150-plus supporting domains were seized with US court authorization; Cloudflare purged associated accounts and scripts.
    • 04Two men were arrested in the UK.
    Koko brief

    AI-powered PhaaS platforms now automate target selection and fraud strategy—not just phishing email drafts.

    Microsoft's takedown of EvilTokens exposes a new tier of criminal capability: AI that scanned compromised inboxes to rank victims by fraud potential, recommended impersonation tactics, and drafted contextually aware lures. The platform compromised over 12,000 inboxes across 10,000+ organizations in roughly seven months. Fifty operational sites and 150-plus supporting domains were seized with US court authorization; Cloudflare purged associated accounts and scripts. Two men were arrested in the UK. The $1,500 entry fee made sophisticated, AI-directed fraud commercially accessible. • Watch: Copycat PhaaS operators adopting identical inbox-analysis AI before defenders build detection baselines.

    Watch: Copycat PhaaS operators adopting identical inbox-analysis AI before defenders build detection baselines.

    In brief · from itpro.com

    Microsoft has disrupted the EvilTokens cyber crime platform in a coordinated campaign that saw 50 websites seized and two men arrested in the UK. The EvilTokens phishing as a service (PhaaS) platform emerged in February on Telegram, giving cyber criminals AI the ability to tailor phishing lures and analyze compromised inboxes to identify high-value targets. In the short time it’s been up and running, the platform has been used to compromise more than 12,000 inboxes at more than 10,000 organizations.

    Read the full article at itpro.com
    Show the full text · 2 min read

    Microsoft has disrupted the EvilTokens cyber crime platform in a coordinated campaign that saw 50 websites seized and two men arrested in the UK. The EvilTokens phishing as a service (PhaaS) platform emerged in February on Telegram, giving cyber criminals AI the ability to tailor phishing lures and analyze compromised inboxes to identify high-value targets. In the short time it’s been up and running, the platform has been used to compromise more than 12,000 inboxes at more than 10,000 organizations. Campaigns have targeted various industries, including wholesale distribution, construction, financial services, real estate, higher education, and healthcare, with most activity in the US, Canada, the UK, Australia, India, and France. Customers paid a $1,500 fee up front to use the service, with a recurring $500 subscription for continued access to the kit and control panel. This kit offered further products, including Antibot redirector, B2B Sender, Office 365 Capture Link, and a Simple Mail Transfer Protocol (SMTP) Sender, each of which carried additional monthly fees. What hackers got with EvilTokens Subscribers were offered personalized lures, with AI used to create targeted phishing emails that were specifically aligned to the target’s role. According to Microsoft, themes used to increase the chances of a response included document signing services, its own cloud services, third-party services such as cloud identity, file hosting and payment or invoicing, as well as other miscellaneous services like voicemail and eFax. Notably, the service was centered around an AI-style chatbot that could analyze a victim’s inbox and help criminals identify trusted relationships, payment authorizations, and sensitive responsibilities, as well as other situations where fraud was most likely to succeed. It could even recommend strategies for carrying out fraud, including drafting messages that impersonated trusted contacts to help criminals trick their victims into taking action. "AI was not simply helping attackers write more convincing messages . It helped them decide who to target, who to impersonate, and how to most effectively exploit the relationship to extract as much money as possible," said Steven Masada, associate general counsel and general manager at Microsoft’s Digital Crimes Unit. How Microsoft tackled EvilTokens Microsoft, with authorization from the US District Court for the Eastern District of Virginia and the help of several other companies, has now seized 50 websites used to operate the service. More than 150 other domains tied to its supporting infrastructure have also been seized. "While EvilTokens used AI to identify targets and prioritize fraud opportunities, Microsoft investigators used reverse engineering and AI-powered tools to analyze evidence, accelerate the investigation, and identify the infrastructure supporting the service," Masada said. Cloudflare, meanwhile, was able to identify the complete list of domain infrastructure and hundreds of Cloudflare accounts used by EvilTokens’ customers. It carried out a technical sweep, blocking hundreds of domains and killing malicious Cloudflare Worker scripts. Where infrastructure couldn't be legally seized, it made use of interstitial warning pages. As a result of the operation, the UK Metropolitan Police Service’s cyber crime team has now arrested two men, aged 32 and 38, suspected of being involved. Authorities also seized digital devices and other items for examination. Both men have been released on police bail while the investigation continues. FOLLOW US ON SOCIAL MEDIA

    Don't miss tomorrow's

    The Daily Pulse in your inbox each morning — sourced and linked.

    How often
    Keep going — across the app