Microsoft disrupts EvilTokens, citing 12,000 compromised inboxes
Microsoft says a court-authorized operation disrupted EvilTokens, an AI-assisted cybercrime service linked to more than 12,000 compromised inboxes at over 10,000 organizations.
Microsoft and its partners disrupted EvilTokens, an AI-assisted cybercrime service the company linked to more than 12,000 compromised email inboxes across over 10,000 organizations worldwide. According to Microsoft, a federal court order enabled the operation to seize 50 sites used to run the service and disable more than 150 other domains tied to its supporting infrastructure.
The action brought together a civil lawsuit, infrastructure removals by industry partners and arrests in the United Kingdom. Microsoft said Metropolitan Police cybercrime officers arrested two men, ages 32 and 38, on September 11 on suspicion of offenses connected with the alleged operation. The company said officers seized items for examination and that both men were later released on conditional police bail.
EvilTokens packaged several stages of an attack into a service sold through Telegram, according to Microsoft’s technical analysis. Microsoft said access cost $1,500 initially and $500 a month. The platform combined phishing delivery and account-token theft with mailbox access, organizational reconnaissance, AI-assisted inbox analysis, target selection and preparation of business-email-compromise messages.
The service abused Microsoft’s legitimate OAuth device-code flow. An attacker initiated an authorization request, then induced a victim to enter the resulting code on Microsoft’s real sign-in page. After the victim authenticated, the attacker obtained account tokens that could provide mailbox access without directly collecting the victim’s password.
Once it gained access, EvilTokens could use AI to summarize and translate messages, identify financial conversations, map roles and trusted relationships, surface high-value targets and recommend impersonation or fraud strategies, Microsoft said. Separate technical work by SpyCloud and Sekoia also documented AI-enabled mailbox analysis and automation aimed at business-email compromise.
SpyCloud reported a narrower figure from its own recaptured-data dataset: 8,708 unique victim accounts with a device-code token capture across 6,585 corporate email domains in 79 countries. That figure is not an independent audit of Microsoft’s totals. The public accounts also differ on when the service started. Microsoft places its launch in February 2026, SpyCloud observed captures from February 18, and Cloudflare says the Telegram operation began in January.
Cloudflare said it joined the coordinated operation on September 15. Its investigators identified domain infrastructure and hundreds of Cloudflare accounts used by EvilTokens customers, removed associated zones and Workers projects, and deployed warning pages where legal seizure was not possible. Cloudflare said it banned hundreds of domains and Workers projects but did not report the same infrastructure totals as Microsoft.
Microsoft and the Health Information Sharing and Analysis Center filed civil action 1:26-cv-3047 in the U.S. District Court for the Eastern District of Virginia. The public court notice lists the case and temporary restraining order. Microsoft said the order directed registries and registrars to transfer or disable associated domains. The notice does not independently enumerate the company’s claimed totals of 50 seized sites and more than 150 disabled domains.
The action gives Microsoft a separate cybercrime enforcement case as the company faces broader AI-policy scrutiny, including a civil-society request for an FTC investigation into book-scanning practices. Microsoft described the EvilTokens case as its Digital Crimes Unit’s first action against an end-to-end AI-enabled cybercrime service and its 40th court-authorized disruption.
More news

xAI launches Team Bots for shared workflows

AWS adds xAI’s Grok 4.7 to Amazon Bedrock

OpenAI adds $5 million and up to $5 million in credits to Lenfest AI program
