Microsoft and coalition partners take down EvilTokens AI phishing-as-a-service platform
On September 22, Microsoft's Digital Crimes Unit announced it had seized 50 websites and disabled more than 150 domains used to run EvilTokens, a phishing-as-a-service platform that put an AI chatbot at the center of enterprise account compromise. The takedown involved eight partner organizations and followed arrests by UK police eleven days earlier.
What happened
The U.S. District Court for the Eastern District of Virginia authorized the action. Microsoft's DCU worked alongside Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs. The Metropolitan Police Service had already arrested two men, aged 32 and 38, on September 11, 2026, in connection with the operation.
EvilTokens exploited OAuth 2.0 device authorization flow, per The Hacker News. Victims received emails from 44 different themed lures (invoices, RFPs, shared documents) that contained malicious links. Clicking a link caused background automation to generate a live device code, which the victim was prompted to enter at the legitimate microsoft.com/devicelogin page. Entering the code handed attackers a valid access and refresh token, giving them persistent inbox access without ever capturing a password.
The service then deployed an AI chatbot to work through the stolen inbox. The chatbot read compromised mailboxes in more than 20 languages, identified trusted relationships and payment authorizations, and drafted impersonation emails to move the fraud forward. Per Microsoft's "On the Issues" blog post, the platform "could even recommend fraud strategies, including drafting messages that impersonated trusted contacts to help criminals trick victims into action." Microsoft tracks the operators internally as Storm-2992 and said the toolkit showed evidence of having been largely built using AI.
SpyCloud captured 8,708 unique compromised accounts across 6,585 corporate email domains in 79 countries. The platform affected organizations in wholesale distribution, construction, financial services, real estate, higher education, and healthcare. Coinbase traced $1.1 million in platform revenue to four Tron blockchain addresses between October 2025 and June 2026. EvilTokens emerged in February 2026; within months, per Microsoft's announcement, it had been linked to more than 12,000 compromised inboxes across more than 10,000 organizations worldwide.
Pricing for the service was structured to attract volume buyers, per the THN report: an Office 365 capture link cost $1,500 as a one-time fee plus $500 per month; an SMTP sender ran $1,000. Trevor Hilligoss, SpyCloud's CIO, described the accessibility plainly: "EvilTokens made them available to anyone for $500 a month."
Disable device code flows you do not need
EvilTokens is the first court-authorized takedown of a platform that wired AI into every stage of a business email compromise chain, from lure personalization through inbox analysis through fraud drafting. The attack method (device code phishing) requires no password capture and bypasses most multi-factor authentication setups that rely on password-triggered prompts. Attackers obtain a valid session token from a real Microsoft login page, which makes email-based detection harder.
For enterprise security and IT teams: device code authentication flows that are not operationally necessary should be disabled at the tenant level via Conditional Access policies. Microsoft's own detection guidance published alongside the announcement details the specific token patterns and lure themes associated with Storm-2992.
OpenAI's formal role in the takedown coalition is also notable. It marks the clearest published example of an AI lab taking operational action against the misuse of its own models in a criminal attack chain, rather than addressing misuse only through terms-of-service enforcement. Enterprise buyers evaluating vendor accountability for downstream model abuse have a concrete data point here.
What to watch next
Microsoft's Digital Crimes Unit typically publishes a full technical report following a major infrastructure disruption. A report on the EvilTokens attack chain methodology, including specific detection rules, would give defenders a more complete picture than the announcement provides. The UK arrests are also early: charges and court proceedings will determine whether the operators face prosecution or extradition, and could surface additional information about the platform's developer network.
Sources
- Disrupting EvilTokens: The AI Chatbot Built for Cybercrime: Microsoft On the Issues, September 22, 2026 (primary)
- Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises: The Hacker News, September 22, 2026 (secondary)
