EvilTokens, a Microsoft device-code phishing kit first detected in February 2026, was sold as a subscription service that allowed criminals to bypass multi-factor authentication (MFA) and silently authenticate as victims to Microsoft 365 applications. What distinguished it from similar kits was its integration of an AI chatbot that could analyse a victim’s inbox, identify high-value targets, impersonate trusted contacts, and recommend fraud strategies to maximise returns.
Microsoft vice president of security research Tanmay Ganacharya told The Register earlier this year that between March 15 and the time of the operation, the platform supported 10 to 15 distinct phishing campaigns every 24 hours. The scale of the operation prompted a coordinated response across the US and UK.
On September 18, officers from London’s Metropolitan Police Service arrested two men, aged 32 and 38, on suspicion of acting as administrators of the EvilTokens website. Both were released on bail while investigations continue. “Phishing services bring misery to thousands, taking money from everyday people across the world,” Detective Inspector Serena D’Adamo, who led the Met’s investigation, said in an emailed statement. “The Met remains committed to holding people to account who facilitate criminal enabling functions and think they can remain undetected.”
In parallel, Microsoft obtained authorisation from the US District Court for the Eastern District of Virginia to seize 50 websites directly hosting the service and disable more than 150 additional domains used for supporting infrastructure. The company also notified affected customers and assisted in remediating compromised accounts. Health-ISAC, a nonprofit threat-sharing organisation for the healthcare sector, joined Microsoft’s legal action as a co-plaintiff after healthcare organisations were identified among the targets.
Other partners in the takedown included Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs. The operation marks the 40th court-authorised disruption by Microsoft’s Digital Crimes Unit (DCU) and the first targeting an end-to-end AI-enabled cybercrime service.
Steven Masada, associate general counsel and general manager of the DCU, warned that the dismantling of EvilTokens does not signal the end of such threats. “The infrastructure supporting EvilTokens has been disrupted, but the model it demonstrated will not disappear with it,” he said in a blog post shared with The Register. “For organisations, the lesson is: assume that once an inbox is compromised, criminals may understand its contents in minutes, not days. Strong identity protections and monitoring remain essential, but organisations should also independently verify requests to change payment information, redirect funds or approve unusual transactions through a trusted second channel.”