This month, Microsoft pursued legal action against EvilTokens, an artificial intelligence-powered platform designed for cybercriminal operations, securing court approval to shut down the service and collaborating with UK law enforcement to apprehend those responsible. Operating via Telegram with a $1,500 entry cost and $500 monthly fee, the platform supplied criminals with AI capabilities to breach accounts, examine stolen email data and devise fraud monetization strategies.

Steven Masada, associate general counsel at Microsoft Digital Crimes Unit, explained that the company filed suit in U.S. District Court alongside Health-ISAC, a cybersecurity organization serving the health sector, enabling them to dismantle the platform and its supporting infrastructure. Cooperation with the Metropolitan Police Service's cybercrime division in the UK resulted in the arrest of two men, ages 32 and 38, in early this month. While Microsoft did not disclose their identities, both were released on bail as investigations continue.

"The two individuals were alleged operators of EvilTokens. We believe others may have supported the service in various capacities," a Microsoft representative stated to Recorded Future News. The Metropolitan Police Service confirmed the arrests as part of an investigation into the online phishing operation, with officers executing warrants at two locations. The two men faced suspicion of creating articles intended for fraud and money laundering. Microsoft had reported the matter to the Metropolitan Police Service in August.

Detective Inspector Serena D'Adamo, who oversaw the investigation, remarked that "Phishing services bring misery to thousands, taking money from everyday people across the world." According to Microsoft, EvilTokens distinguished itself through its capacity to streamline multiple elements of a criminal's operational workflow. "EvilTokens drew on capabilities from multiple AI models. As we note in our blog, OpenAI was an important partner in this disruption effort," a Microsoft representative said, without elaborating on other AI systems involved.

The platform proved particularly dangerous by furnishing criminals with detailed blueprints for financial fraud and scams, examining victim email accounts and pinpointing exploitation opportunities. The AI chatbot enabled offenders to "identify trusted relationships, payment authorizations and sensitive responsibilities, and other circumstances where fraud was most likely to succeed." Masada elaborated that the system could "recommend fraud strategies, including drafting messages that impersonated trusted contacts to help criminals trick victims into taking action."

"In short, AI was not simply helping attackers write more convincing messages. It helped them decide who to target, who to impersonate, and how to most effectively exploit the relationship to extract as much money as possible," Masada added. The platform launched in February 2026 and was connected to over 12,000 compromised email accounts spanning more than 10,000 organizations globally, with targeted organizations concentrated in the U.S., Canada, U.K., Australia, India and France. Microsoft collaborated with numerous firms to seize 50 websites operating the service and disable 150 additional domains connected to its infrastructure.

'Evil' authentication codes

Victims received fraudulent messages employing 44 distinct themes, from false invoices to file-sharing prompts, typically containing malicious links, PDFs or other file formats. The platform featured numerous ready-made phishing templates and landing pages with an AI assistant designed to customize emails for specific targets. Microsoft noted that manually analyzing breached inboxes previously required days or weeks for criminals to uncover fraud prospects, yet EvilTokens largely automated this process in minutes.

"Its AI tools could summarize and translate emails, surface financial conversations, map organizational roles, identify trusted relationships, and recommend potential targets," Masada explained. "Preset prompts offered to find wire-transfer discussions, identify the organization's 'money movers,' locate vendor invoices, and determine the best people to impersonate." Among the platform's most frequently exploited capabilities was the device code phishing mechanism, which capitalized on authentication limitations in devices lacking conventional sign-in support, such as smart televisions, printers, video conferencing systems and Teams devices.

Users receive a short code on their device and are instructed to input it into a browser on another device to finish authentication. However, when a threat actor initiates the flow instead, they furnish the user with a code via a phishing message. Upon entering the code, victims unknowingly grant cybercriminals access and authorize their session without disclosing passwords. Victims granted complete email account access without sharing credentials, and this access remained functional even after password changes.

Examination revealed that EvilTokens was substantially "vibe coded"—terminology describing platforms constructed primarily through large language model utilization. The service included customer support functions, administrative dashboards and mechanisms to streamline major components of the financial exploitation workflow. The operation depended on a network of hosting services, cloud infrastructure, AI systems and additional resources. Microsoft coordinated with Cloudflare, Coinbase, The Shadowserver Foundation, TRM Labs and other organizations to dismantle the platform.

Microsoft representatives noted that the operation demonstrated how AI-driven fraud has evolved beyond simply generating convincing phishing communications to automating and tailoring nearly all dimensions of criminal activity. This takedown marks the 40th court-authorized disruption by Microsoft Digital Crimes Unit and represents the organization's initial action against what they designate an "end-to-end AI-enabled cybercrime service." In June, Microsoft dismantled hundreds of servers and domains associated with cybercrime-as-a-service operations distributing SocGholish, Amadey and StealC malware. The company had previously targeted additional cybercriminal platforms including RaccoonO365 and RedVDS throughout the preceding year.