Microsoft Takes Down EvilTokens Phishing Service Affecting 12,000 Inboxes
Microsoft and partners dismantled the EvilTokens phishing operation, which compromised over 12,000 inboxes across 10,000 organizations.
Microsoft disrupts EvilTokens phishing service that gave criminals access to 12,000 inboxes
A coordinated effort by law enforcement and private-sector entities has dismantled the EvilTokens phishing operation, which compromised over 12,000 inboxes across more than 10,000 organizations. The initiative, led by Microsoft, involved collaboration with Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs. With court authorization from the U.S. District Court for the Eastern District of Virginia, the coalition seized 50 websites and disabled 150 domains linked to the service’s infrastructure. Microsoft confirmed it alerted affected users, assisted in remediation efforts, and shared threat intelligence to support ongoing investigations.
AI-Driven Fraud Mechanisms
EvilTokens, launched in February 2026, enabled attackers to gain unauthorized access to email accounts through a phishing scheme. Victims were tricked into entering authentication codes on Microsoft’s legitimate sign-in page, inadvertently granting access without exposing their passwords. This access could persist even after password resets if sessions and tokens were not revoked, according to Masada. Once infiltrated, the platform’s AI tools analyzed email content to summarize messages, translate correspondence, identify financial discussions, map organizational roles, and detect trusted relationships. Predefined prompts allowed users to locate wire transfer conversations, vendor invoices, and key financial contacts, while the AI generated messages impersonating legitimate stakeholders.
“The AI streamlined target selection and fraud execution, reducing the technical barriers for cybercriminals,” Masada noted.
Global Impact and Affected Sectors
Microsoft identified the highest concentrations of compromised accounts in the U.S., Canada, the U.K., Australia, India, and France. The service targeted organizations across diverse industries, including wholesale distribution, construction, financial services, higher education, and healthcare.
Operational Model and Financial Structure
EvilTokens operated as a subscription-based service, available on Telegram for a $1,500 setup fee and a $500 monthly charge. It integrated account compromise, mailbox analysis, and fraud preparation into a unified interface, consolidating capabilities that previously required expertise in identity attacks, cloud systems, social engineering, and financial fraud.
Post-Disruption Implications
While the infrastructure supporting EvilTokens has been neutralized, Masada warned that the operational model it demonstrated will persist. “This case highlights the convergence of compromised accounts and AI-driven tools to accelerate financial fraud,” he said. Organizations are urged to assume that a compromised inbox may be fully understood within minutes.
Recommendations for Organizations
Microsoft advised enterprises to implement robust identity protections and continuous monitoring. Additionally, entities should verify requests for payment changes, fund redirections, or unusual transactions through a trusted secondary communication channel. “Proactive verification remains critical to mitigating risks associated with account compromises,” Masada concluded.
Conclusion
The disruption of EvilTokens underscores the evolving tactics of cybercriminals and the necessity of cross-sector collaboration to counter sophisticated threats.
FAQs
What was EvilTokens?
EvilTokens was a phishing service that compromised over 12,000 inboxes by tricking users into entering authentication codes on Microsoft’s sign-in page, granting attackers access to email accounts.
How did Microsoft and partners dismantle EvilTokens?
Through a coordinated effort involving law enforcement and private-sector entities, Microsoft seized 50 websites and disabled 150 domains linked to EvilTokens’ infrastructure with court authorization.
What industries were affected?
EvilTokens targeted organizations in wholesale distribution, construction, financial services, higher education, and healthcare across the U.S., Canada, the U.K., Australia, India, and France.
What recommendations did Microsoft provide?
Microsoft advised enterprises to implement robust identity protections, continuous monitoring, and verify payment changes or unusual transactions through trusted secondary channels.
