Microsoft has shut down EvilTokens, a subscription-based cybercrime service sold via Telegram that used AI tools to break into Microsoft accounts and mine stolen inboxes for payment details and business contacts. The company said the service compromised roughly 12,000 accounts across 10,000 organizations by abusing Microsoft's device-code sign-in process, and it seized 50 websites and 150 domains via legal action. UK police separately arrested two men suspected of running the operation.
techspot.com
· 2026-09-23
Microsoft announced it coordinated an industry-wide disruption of EvilTokens, a subscription phishing service sold via Telegram since February that used an AI chatbot to help criminals analyze compromised inboxes and craft convincing fraud emails. The platform compromised 12,000 accounts across 10,000 organizations worldwide, mostly in the US, and Microsoft seized 50 websites and 150 domains as UK police arrested two suspects.
arstechnica.com
· 2026-09-22
Microsoft's Digital Crimes Unit, working with Health-ISAC, law enforcement, and SpyCloud, dismantled the infrastructure behind EvilTokens, a phishing-as-a-service platform that had compromised over 12,000 Microsoft accounts across more than 10,000 organizations. The UK's Metropolitan Police arrested two men, aged 32 and 38, suspected of administering the site, following raids in Canary Wharf and Nine Elms; both were released on bail.
bleepingcomputer.com
· 2026-09-22