Microsoft disrupts EvilTokens phishing-as-a-service platform
The AI-powered platform compromised more than 12,000 email accounts across 10,000 organizations in under eight months, automating the post-compromise fraud workflow from inbox to payout.
TL;DR
Microsoft, working with industry partners, seized 50 websites and disabled more than 175 domains tied to EvilTokens, a phishing-as-a-service platform launched in February 2026. The service enabled approximately 1,000 cybercriminals to compromise over 12,000 Microsoft customer inboxes across 10,000+ organizations globally. EvilTokens used an AI chatbot to analyze victim inboxes and identify trusted relationships and payment authorizations for fraud. Microsoft identified two UK-based operators (Felix Utomi and Waidi Segun Adams) whom London's Metropolitan Police arrested September 18 on suspicion of fraud and money laundering. Coinbase traced roughly $1.1 million in platform revenue. FBI IC3 complaints linked to EvilTokens represent at least $1.7 million in reported losses.
EvilTokens operated for less than eight months before its infrastructure was dismantled, joining Tycoon 2FA (March 2026) and RaccoonO365 (September 2025) in a sequence of Microsoft-led phishing-kit takedowns. What distinguished EvilTokens was the depth of its AI integration. The platform didn't just automate credential harvesting and MFA bypass, it gave attackers a post-compromise analysis engine.
Steven Masada, assistant general counsel at Microsoft's Digital Crimes Unit, described the AI chatbot as a tool that "helped attackers decide who to target, who to impersonate, and how to most effectively exploit the relationship to extract as much money as possible." The bot sifted through compromised inboxes to surface payment authorizations, trusted vendor relationships, and sensitive financial details, work that previously required a skilled operator spending hours inside each account.
Cisco Talos research on ARToken, an affiliate platform sharing infrastructure with EvilTokens, documented additional post-compromise capabilities including inbox rule manipulation and shared access links. Talos characterized the broader ecosystem as "a complete BEC operations environment," not merely a phishing kit.
The $1.7 million in IC3 complaints and $1.1 million in traced cryptocurrency revenue are both floors, not ceilings. Microsoft acknowledged it "cannot estimate the total fraud" and considers these figures conservative given underreporting. Victims concentrated in the US, Canada, UK, Australia, India, and France.
For defenders, the EvilTokens model reinforces that session-token theft and post-authentication mailbox abuse are now default capabilities in phishing platforms targeting finance and accounts-payable staff. The AI component shortens the window between compromise and fraud, making detection speed more critical than it was even a year ago.
Published ·Deep Fathom