UK police arrest two in takedown of AI-powered EvilTokens phishing service

Microsoft seizes 50 websites and disables 150+ domains in coordinated operation targeting sophisticated MFA-bypass kit

By LineZotpaper
Published
Read Time3 min
Sources2 outlets
A coalition led by Microsoft and the London Metropolitan Police has disrupted the EvilTokens phishing service, arresting two alleged administrators and seizing more than 50 websites used to operate the AI-enhanced platform that compromised 12,000 email inboxes across 10,000 organisations worldwide.

EvilTokens, a Microsoft device-code phishing kit first detected in February 2026, was sold as a subscription service that allowed criminals to bypass multi-factor authentication (MFA) and silently authenticate as victims to Microsoft 365 applications. What distinguished it from similar kits was its integration of an AI chatbot that could analyse a victim’s inbox, identify high-value targets, impersonate trusted contacts, and recommend fraud strategies to maximise returns.

Microsoft vice president of security research Tanmay Ganacharya told The Register earlier this year that between March 15 and the time of the operation, the platform supported 10 to 15 distinct phishing campaigns every 24 hours. The scale of the operation prompted a coordinated response across the US and UK.

On September 18, officers from London’s Metropolitan Police Service arrested two men, aged 32 and 38, on suspicion of acting as administrators of the EvilTokens website. Both were released on bail while investigations continue. “Phishing services bring misery to thousands, taking money from everyday people across the world,” Detective Inspector Serena D’Adamo, who led the Met’s investigation, said in an emailed statement. “The Met remains committed to holding people to account who facilitate criminal enabling functions and think they can remain undetected.”

In parallel, Microsoft obtained authorisation from the US District Court for the Eastern District of Virginia to seize 50 websites directly hosting the service and disable more than 150 additional domains used for supporting infrastructure. The company also notified affected customers and assisted in remediating compromised accounts. Health-ISAC, a nonprofit threat-sharing organisation for the healthcare sector, joined Microsoft’s legal action as a co-plaintiff after healthcare organisations were identified among the targets.

Other partners in the takedown included Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs. The operation marks the 40th court-authorised disruption by Microsoft’s Digital Crimes Unit (DCU) and the first targeting an end-to-end AI-enabled cybercrime service.

Steven Masada, associate general counsel and general manager of the DCU, warned that the dismantling of EvilTokens does not signal the end of such threats. “The infrastructure supporting EvilTokens has been disrupted, but the model it demonstrated will not disappear with it,” he said in a blog post shared with The Register. “For organisations, the lesson is: assume that once an inbox is compromised, criminals may understand its contents in minutes, not days. Strong identity protections and monitoring remain essential, but organisations should also independently verify requests to change payment information, redirect funds or approve unusual transactions through a trusted second channel.”

§

Analysis

Why This Matters

  • The takedown demonstrates that law enforcement and tech companies can disrupt sophisticated, AI-enhanced phishing operations, but the speed at which new services emerge means organisations must remain vigilant.
  • The use of AI to automate reconnaissance and social engineering lowers the barrier for attackers, potentially increasing the frequency and effectiveness of targeted phishing attacks.
  • Healthcare organisations, already strained by cybersecurity incidents, were specifically targeted, highlighting the real-world consequences of credential theft for critical sectors.

Background

EvilTokens was a device-code phishing kit that exploited a legitimate Microsoft authentication flow used by devices like smart TVs and printers that cannot display full web pages. By tricking users into entering a generated code on a legitimate Microsoft login page, attackers could capture session tokens and bypass MFA. The service, sold on underground forums, included an AI chatbot that could read a victim’s emails and suggest the most effective impersonation or fraud strategy. Within months, it had compromised thousands of accounts globally. The operation against EvilTokens is part of a broader trend where law enforcement increasingly targets the infrastructure of cybercrime-as-a-service platforms.

Key Perspectives

Law enforcement (Met Police): The arrests send a signal that administrators of criminal enabling platforms will be pursued, even if they operate from overseas. Detective Inspector D’Adamo emphasised the impact on everyday victims and the commitment to holding facilitators accountable.

Microsoft and partners: The disruption is a technical victory, but Microsoft’s DCU acknowledges that the AI-powered model will persist. The focus is on helping affected organisations remediate and urging adoption of stronger identity protections, such as requiring out-of-band verification for sensitive transactions.

Victims and the healthcare sector: Health-ISAC’s involvement shows that targeted industries are seeking to collaborate with law enforcement and tech firms. The breach of 12,000 inboxes means many organisations will need to assess the extent of data exposure and potential follow-on attacks.

What to Watch

  • Whether the two arrested men are charged or further suspects emerge as the Met investigation continues.
  • Emergence of copycat AI-enabled phishing services that mimic EvilTokens’ capabilities.
  • Microsoft’s ongoing efforts to harden device-code authentication flows to make such attacks harder to execute.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.