Skip to content
TECH CEO Daily

Microsoft EvilTokens takedown hits AI phishing service tied to 12,000 hacked inboxes

The court-backed action targeted a subscription service that paired device-code phishing with an AI chatbot that mined stolen mailboxes for fraud opportunities.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Microsoft says EvilTokens compromised more than 12,000 inboxes at over 10,000 organizations after launching in February 2026.
  • 2Its AI chatbot summarized mail, mapped decision-makers and flagged wire-transfer talks to help criminals plan payment fraud.
  • 3Microsoft seized 50 websites and disabled 150-plus domains; London police arrested two men aged 32 and 38.

The news

Microsoft (MSFT) announced the EvilTokens takedown on September 22, disrupting a subscription phishing service that the company said compromised more than 12,000 email inboxes at over 10,000 organizations. A U.S. federal court authorized the action, and London police arrested two men on suspicion of offenses connected with the alleged operation of the service.

According to a blog post by Steven Masada, who leads Microsoft's Digital Crimes Unit, EvilTokens launched in February 2026 and relied on device-code attacks. Victims were tricked into typing a code on Microsoft's real sign-in page, which quietly granted the attackers ongoing access to their mailbox without ever capturing a password. The Register noted this approach lets criminals get around multifactor authentication, and reported that Microsoft observed 10 to 15 distinct EvilTokens campaigns launching every 24 hours since March 2026.

What set the service apart was an AI chatbot built for fraud. Microsoft said it could summarize and translate emails, map an organization's roles and trusted relationships, surface conversations about wire transfers and invoices, recommend potential targets and suggest how to impersonate contacts. Microsoft described it as the Digital Crimes Unit's first action against an end-to-end AI-enabled cybercrime service and its 40th court-authorized disruption.

Microsoft said the U.S. District Court for the Eastern District of Virginia approved the operation, with Health-ISAC, a healthcare security information-sharing group, as co-plaintiff. Partners included Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, the Shadowserver Foundation and TRM Labs. Microsoft seized 50 websites and more than 150 additional domains were disabled.

London's Metropolitan Police arrested two men, aged 32 and 38, who were released on bail pending investigation, Microsoft said. Microsoft said access was sold through Telegram for a $1,500 initiation fee and a recurring $500 subscription; The Hacker News reported that the $500 fee was monthly. The Hacker News also reported that Microsoft tracks the group behind EvilTokens as Storm-2992, and that Coinbase said it traced about $1.1 million in platform revenue across four Tron addresses between October 2025 and June 2026, a window that begins before Microsoft's stated February 2026 launch.

The numbers

Compromised email inboxes
More than 12,000
Organizations affected
More than 10,000
Websites seized
50
Additional domains disabled
More than 150
Service pricing
$1,500 initiation plus recurring $500 subscription
Revenue traced by Coinbase (Oct 2025-Jun 2026, reported)
About $1.1 million

Why CEOs should care

For CFOs and controllers, the threat is payment fraud, not just data theft. Microsoft said the chatbot was designed to find money movers, vendor invoices and wire-transfer discussions. Its advice is to independently verify any request to change payment details, redirect funds or approve unusual transactions through a trusted second channel, such as a known phone number. Finance teams should make that a written, audited control rather than a habit.

For CISOs, device-code phishing deserves specific attention. Because victims sign in on a genuine Microsoft page, standard training that tells staff to check the web address does not help, and multifactor authentication does not stop it. Security teams should review whether device-code sign-in is needed at all, restrict it with conditional access policies where possible, and monitor for new device registrations and unusual mailbox access. Microsoft warned that once an inbox falls, attackers may understand its contents in minutes rather than days.

For boards, the case is an early marker of how AI changes criminal economics. Tasks that once took a skilled fraudster days of reading, such as working out who approves payments, are now automated and sold by subscription. Ask whether fraud controls assume attackers will be slow and manual, and whether incident response plans cover mailbox compromise as a finance event.

The bigger picture

Microsoft said the victims were concentrated in the United States, Canada, the United Kingdom, Australia, India and France, and spanned wholesale distribution, construction, financial services, real estate, higher education and healthcare. That breadth reflects how business email compromise targets any company that pays invoices.

The operation also shows the private sector's growing role in disrupting cybercrime. Civil court orders let Microsoft seize infrastructure quickly, while partners such as Coinbase and TRM Labs help trace payments and cloud providers pull hosting.

What’s next

Watch for charges or further arrests from the Metropolitan Police investigation, and for signs that EvilTokens operators or copycats rebuild on new domains. The Digital Crimes Unit has already run earlier 2026 operations against the Tycoon 2FA phishing service and a cybercrime service it calls Fox Tempest. Companies should check sign-in logs for device-code authentications dating back to February 2026, when Microsoft says the service launched.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

MicrosoftEvilTokensPhishingBusiness email compromise

Earlier coverage of Microsoft

All Microsoft coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.