Microsoft Disrupted EvilTokens Cybercrime Platform

The platform automated phishing and inbox compromises for over 10,000 organizations worldwide.

Updated on Sept. 26, 2026 in Cybersecurity

Microsoft Disrupted EvilTokens Cybercrime Platform

Live Poll

Do you trust your current digital security measures to protect you from AI-powered fraud?

Microsoft has dismantled the EvilTokens cybercrime platform, an operation that utilized AI-driven phishing to breach more than 12,000 email inboxes. UK authorities concurrently arrested two individuals in connection with the platform.

Why it matters

The platform represented a shift toward automating complex cyber fraud tasks that previously required manual analysis, lowering the barrier for entry into high-level business email compromise. By targeting organizations with automated hierarchy mapping, it accelerated the scale of account takeovers.

EvilTokens operated by charging a $1,500 initiation fee plus a $500 recurring subscription, significantly lower than the manual labor costs of traditional spear-phishing. Microsoft's enforcement action disabled 150 domains and seized 50 websites associated with the infrastructure.

The players

Microsoft

A global technology company providing cloud infrastructure and security software that monitors and protects enterprise identity systems.

UK authorities

Law enforcement agencies responsible for investigating and prosecuting cybercrime activities within the United Kingdom.

The details

The platform leveraged artificial intelligence to scan communications for financial context, identifying key relationships and internal hierarchies within targeted organizations. Attackers then used device-code phishing to trick users into providing access through a legitimate Microsoft sign-in process, allowing them to bypass traditional password-based security measures.

Timeline

  1. February 2026: EvilTokens platform launched.

  2. September 2026: Microsoft disrupted the EvilTokens platform.

The Tech Race

This action fits into the broader crackdown on Phishing-as-a-Service (PhaaS) platforms that monetize automated compromise techniques. By removing the infrastructure, Microsoft is attempting to break the current cycle of low-cost, high-volume automated phishing.

Organizations should review their device-code authentication logs for unauthorized sign-ins that may have occurred since February 2026. Because this platform automated the identification of financial relationships, security teams should focus on auditing permissions within high-value email chains.

The takeaway

The disruption of EvilTokens highlights the ongoing vulnerability of device-code authentication in enterprise environments. Security teams should monitor the legal proceedings of the arrested suspects for future intelligence on evolving phishing methodologies.

Further reading

For more on the current landscape of digital infrastructure protection, see the Cybersecurity section.

Source note: This article includes information reported by Facebook.

Live Poll

Do you trust your current digital security measures to protect you from AI-powered fraud?

Microsoft Disrupted EvilTokens Cybercrime Platform