The news
Microsoft (MSFT) announced the EvilTokens takedown on September 22, disrupting a subscription phishing service that the company said compromised more than 12,000 email inboxes at over 10,000 organizations. A U.S. federal court authorized the action, and London police arrested two men on suspicion of offenses connected with the alleged operation of the service.
According to a blog post by Steven Masada, who leads Microsoft's Digital Crimes Unit, EvilTokens launched in February 2026 and relied on device-code attacks. Victims were tricked into typing a code on Microsoft's real sign-in page, which quietly granted the attackers ongoing access to their mailbox without ever capturing a password. The Register noted this approach lets criminals get around multifactor authentication, and reported that Microsoft observed 10 to 15 distinct EvilTokens campaigns launching every 24 hours since March 2026.
What set the service apart was an AI chatbot built for fraud. Microsoft said it could summarize and translate emails, map an organization's roles and trusted relationships, surface conversations about wire transfers and invoices, recommend potential targets and suggest how to impersonate contacts. Microsoft described it as the Digital Crimes Unit's first action against an end-to-end AI-enabled cybercrime service and its 40th court-authorized disruption.
Microsoft said the U.S. District Court for the Eastern District of Virginia approved the operation, with Health-ISAC, a healthcare security information-sharing group, as co-plaintiff. Partners included Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, the Shadowserver Foundation and TRM Labs. Microsoft seized 50 websites and more than 150 additional domains were disabled.
London's Metropolitan Police arrested two men, aged 32 and 38, who were released on bail pending investigation, Microsoft said. Microsoft said access was sold through Telegram for a $1,500 initiation fee and a recurring $500 subscription; The Hacker News reported that the $500 fee was monthly. The Hacker News also reported that Microsoft tracks the group behind EvilTokens as Storm-2992, and that Coinbase said it traced about $1.1 million in platform revenue across four Tron addresses between October 2025 and June 2026, a window that begins before Microsoft's stated February 2026 launch.
The numbers
- Compromised email inboxes
- More than 12,000
- Organizations affected
- More than 10,000
- Websites seized
- 50
- Additional domains disabled
- More than 150
- Service pricing
- $1,500 initiation plus recurring $500 subscription
- Revenue traced by Coinbase (Oct 2025-Jun 2026, reported)
- About $1.1 million
Why CEOs should care
For CFOs and controllers, the threat is payment fraud, not just data theft. Microsoft said the chatbot was designed to find money movers, vendor invoices and wire-transfer discussions. Its advice is to independently verify any request to change payment details, redirect funds or approve unusual transactions through a trusted second channel, such as a known phone number. Finance teams should make that a written, audited control rather than a habit.
For CISOs, device-code phishing deserves specific attention. Because victims sign in on a genuine Microsoft page, standard training that tells staff to check the web address does not help, and multifactor authentication does not stop it. Security teams should review whether device-code sign-in is needed at all, restrict it with conditional access policies where possible, and monitor for new device registrations and unusual mailbox access. Microsoft warned that once an inbox falls, attackers may understand its contents in minutes rather than days.
For boards, the case is an early marker of how AI changes criminal economics. Tasks that once took a skilled fraudster days of reading, such as working out who approves payments, are now automated and sold by subscription. Ask whether fraud controls assume attackers will be slow and manual, and whether incident response plans cover mailbox compromise as a finance event.
The bigger picture
Microsoft said the victims were concentrated in the United States, Canada, the United Kingdom, Australia, India and France, and spanned wholesale distribution, construction, financial services, real estate, higher education and healthcare. That breadth reflects how business email compromise targets any company that pays invoices.
The operation also shows the private sector's growing role in disrupting cybercrime. Civil court orders let Microsoft seize infrastructure quickly, while partners such as Coinbase and TRM Labs help trace payments and cloud providers pull hosting.
What’s next
Watch for charges or further arrests from the Metropolitan Police investigation, and for signs that EvilTokens operators or copycats rebuild on new domains. The Digital Crimes Unit has already run earlier 2026 operations against the Tycoon 2FA phishing service and a cybercrime service it calls Fox Tempest. Companies should check sign-in logs for device-code authentications dating back to February 2026, when Microsoft says the service launched.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error
Companies in this story








