Signum
Feed
Useful signal22 Sept 2026high confidence

Microsoft leads takedown of "EvilTokens" AI-assisted phishing/fraud platform, disrupting scheme that compromised 12,000 Microsoft accounts

Microsoft, working with SpyCloud and other partners, used legal process to seize 50 websites and 150 domains used to run EvilTokens, a subscription-based ($1,500 initial + $500/month) crime-as-a-service platform that used an AI chatbot to analyze compromised inboxes and craft business email compromise (BEC) fraud. The platform had compromised 12,000 Microsoft accounts across 10,000 organizations since its February launch via device-code OAuth phishing. The UK's Metropolitan Police arrested two men suspected of operating the platform.

CapabilityGovernanceAccessLabour

Entities: Microsoft, EvilTokens, SpyCloud, Metropolitan Police Service, Microsoft Entra, Telegram

72Useful signal
1 source
0 primary
Was this useful?
01

What happened

Microsoft, working with security firm SpyCloud, used legal action to seize 50 websites and 150 domains behind "EvilTokens", a subscription crime-as-a-service platform ($1,500 signup plus $500 a month) that used an AI chatbot to mine hacked inboxes for business email compromise fraud. Microsoft says the platform compromised 12,000 Microsoft accounts across 10,000 organisations since launching in February, using device-code OAuth phishing as its entry point. The UK's Metropolitan Police arrested two men suspected of running it.

02

Why it matters

This is a concrete, already-completed enforcement action with unusually specific numbers (accounts, domains, pricing, timeline), which is rarer than most "AI crime" stories that stay vague. It confirms AI tools are being packaged and sold as commercial services to accelerate BEC fraud, and it gives security teams a clear, actionable lesson: harden or disable device-code OAuth flows and put independent verification on payment and fund-transfer requests. The direct impact is limited to the 10,000 affected organisations and the broader signal that this attack pattern exists; it does not indicate a wider crackdown or systemic change in cybercrime economics.

03

What is noise

Microsoft's framing that AI cuts fraud analysis "from days to minutes" is a vendor talking point designed to sell Microsoft's own identity and monitoring products, not an independently verified capability claim. Taking down one platform and arresting two operators is routine cybercrime enforcement dressed up as a bigger AI-era turning point; copycat services with similar pricing and tooling can and likely will reappear. No primary evidence links (the actual Microsoft blog post, court filings, or Met Police statement) were captured, so key details rest on secondhand reporting.

04

Watch next

  1. 01Whether Microsoft or SpyCloud publish the underlying blog post, court filing or technical writeup with verifiable detail on the AI chatbot's actual capability, not just marketing language
  2. 02Whether the two arrested men are charged and what the Metropolitan Police case reveals about how the platform operated and who its customers were
  3. 03Whether similar device-code OAuth phishing kits or BEC-as-a-service platforms surface in the next 3-6 months, which would show this was one node in a persistent market rather than an isolated takedown

Coverage

1 story

More capability signals

Full feed →