Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Microsoft and UK Police Dismantle AI-Powered ‘EvilTokens’ Phishing Service

Дата публикации: 23-09-2026 10:29:11

Microsoft has disrupted EvilTokens, an AI-powered cybercrime platform, working with U.K. police to arrest two suspected operators. U.K. officers executed warrants at two locations last Friday and arrested two men on suspicion of making articles for use in fraud and money laundering. Both were released on bail while the investigation continues.  Microsoft reported the platform […]

Основное содержимое страницы с новостью.

Phishing Infrastructure Dismantled - Inbox - AI Phishing - Evidence Seals

Key Takeaways

  • UK arrests: The Metropolitan Police Service arrested two men on September 11, 2026, seizing digital devices as part of the EvilTokens investigation.

  • Platform scale: EvilTokens compromised over 12,000 inboxes across more than 10,000 organizations spanning finance, healthcare, higher education, and more.

  • Milestone action: The takedown is Microsoft Digital Crimes Unit's 40th court-authorized disruption since 2008, and its first against an end-to-end AI-enabled cybercrime service.

Microsoft has disrupted EvilTokens, an AI-powered cybercrime platform, working with U.K. police to arrest two suspected operators. U.K. officers executed warrants at two locations last Friday and arrested two men on suspicion of making articles for use in fraud and money laundering. Both were released on bail while the investigation continues. 

Microsoft reported the platform to London's Metropolitan Police Service in August.

Lawsuit and Arrests Take Down the Platform

With authorization from the U.S. District Court for the Eastern District of Virginia, Microsoft and health-sector non-profit Health-ISAC – which joined as co-plaintiff because healthcare organizations were among those targeted – worked with Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs to dismantle the service, seizing 50 websites and disabling more than 150 additional domains. 

EvilTokens store on Telegram | Source: Microsoft

EvilTokens store on Telegram | Source: Microsoft

In the U.K., the Metropolitan Police Service's cybercrime team arrested two men, aged 32 and 38, on September 11, seizing digital devices for examination; both were released on bail. 

"Phishing services bring misery to thousands, taking money from everyday people across the world," said Detective Inspector Serena D'Adamo, who led the investigation. A Microsoft spokesperson said others may have supported the service beyond the two arrested men.

How EvilTokens Automated Fraud

Launched in February 2026 and sold via Telegram, EvilTokens was linked within months to over 12,000 compromised inboxes across more than 10,000 organizations, with the heaviest victim concentrations in the U.S., Canada, U.K., Australia, India, and France, spanning wholesale distribution, construction, financial services, real estate, higher education, and healthcare. 

EvilTokens “Essential Tools” optimized for cybercrime | Source: Microsoft

EvilTokens “Essential Tools” optimized for cybercrime | Source: Microsoft

Victims were tricked into completing Microsoft's legitimate device-code sign-in flow, unknowingly handing attackers account access without revealing a password – access that could persist even after a reset if tokens weren't separately revoked. 

Once inside, its AI tools summarized and translated emails, mapped organizational roles, flagged wire-transfer discussions, and recommended which employees to impersonate.

A Broader Crackdown, Built With AI Itself

Investigators found large portions of EvilTokens were "vibe coded" using multiple AI models. Microsoft says the case reflects a broader trend – increasingly capable, accessible AI being used to scale fraud and impersonation. 

The company's guidance for organizations is to:

  • assume criminals can understand a compromised inbox within minutes rather than days,
  • independently verify any request to change payment details or approve unusual transactions through a trusted second channel.

The company also worked with Cloudflare, Coinbase, The Shadowserver Foundation, and TRM Labs. This marks Microsoft Digital Crimes Unit's 40th court-authorized disruption overall and its first against what it calls an "end-to-end AI-enabled cybercrime service," following earlier actions against RaccoonO365 and RedVDS.

A June report presented EvilTokens as a phishing-as-a-service (PhaaS) kit built to compromise Microsoft 365 accounts by abusing the OAuth 2.0 device authorization grant flow.

Explore More

Most Popular

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1FCA and partners continues crackdown on illegal crypto trading08.3201-01-1970
2Firms crack down on money mules but need to do more09.9201-01-1970
3India Cracks Down on 15 Crypto Platforms011.225-09-2026
4OpenAI says its models engaged with US government websites in misbehavior disclosure05.9226-09-2026
5Microsoft is "reimagining" Copilot with Home, Code, and Autopilot012.6625-09-2026
6Microsoft Weekly: New Windows 11 preview updates, fresh Surface lineup, and more014.8826-09-2026
7В Британии сообщили о «крупном инциденте» у базы ВВС США09.327-09-2026
8Microsoft drafts ‘humanist’ AI code of conduct amid safety debate06.9615-09-2026
9Qui se cache derrière Pangram, la traqueuse de la "grande suspicion" IA06.9425-09-2026
10Knapp 10.000 Rufnummern von Cyberkriminellen abgeschaltet017.7925-09-2026

Классификация: Происшествия. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 9.78. Источник: www.technadu.com.