Microsoft seizes 50 EvilTokens phishing sites, two arrested in UK
Microsoft and partner organizations dismantled EvilTokens, a phishing-as-a-service operation that used AI tools and device code phishing to compromise over 12,000 inboxes across more than 10,000 organizations. Following a US court-enabled legal action, Microsoft seized 50 websites and disabled over 150 additional domains linked to the operators, tracked as Storm-2992. The UK's Metropolitan Police also arrested two men connected to the scheme this month; both were released on bail pending further investigation.
GoKawiil's interpretation of the reporting above, not reported fact.
The scale of the breach suggests automated, AI-assisted phishing kits are lowering the barrier for large business email compromise campaigns targeting Microsoft 365 accounts. The takedown shows how legal seizures paired with law enforcement arrests can be used to disrupt phishing-as-a-service infrastructure, though the ongoing UK investigation indicates the full network of operators and customers may not yet be fully accounted for.
- EvilTokens compromised over 12,000 inboxes across 10,000+ organizations using AI-powered phishing tools.
- Microsoft seized 50 websites and disabled 150+ domains tied to the service's infrastructure.
- UK police arrested two men connected to the operation, who remain on bail as investigations continue.
YubiKey 5C NFC Security Key — Phishing-as-a-service platforms like EvilTokens thrive on stealing credentials and session tokens, but hardware security keys like the YubiKey make that kind of account takeover far harder to pull off. Using FIDO2/WebAuthn authentication tied to a physical key means attackers can't simply phish a code or token to get into your inbox. It's a simple way to harden your accounts against exactly the kind of BEC attacks described in the article.
See YubiKey 5C NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.Source: darkreading.com — Alexander Culafi, 2026-09-22
Published there as: “Microsoft Disrupts EvilTokens Device Code Phishing Service”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.