UK cops arrest 2 EvilTokens suspects, Microsoft seizes 50 phishing kit websites
Used by crims to compromise 12K+ email inboxes across 10K+ global orgs
Law enforcement and technology companies, spearheaded by Microsoft, have dismantled the EvilTokens phishing service, arresting suspects, dismantling over 50 websites, and alerting victims of affected email accounts. The AI-driven EvilTokens, launched in February, swiftly compromised 12,000 email inboxes across more than 10,000 organizations globally.
Unlike other phishing services, EvilTokens utilized AI to analyze victims' inboxes, helping criminals identify targets, trusted contacts, and the most profitable fraudulent strategies. On September 18, UK's Metropolitan Police Service apprehended two men, aged 32 and 38, suspected of administering the EvilTokens website. Both have been released on bail as the investigation proceeds.
Health-ISAC, a nonprofit organization, joined Microsoft's legal efforts due to the healthcare sector's high-profile targets. Following a legal order from the US District Court for the Eastern District of Virginia, Microsoft and Health-ISAC worked with various tech firms to take down EvilTokens' platform, resulting in Microsoft's 40th court-ordered cybercrime disruption.
The incident underscores the importance of robust identity protections and vigilant monitoring, as criminals may quickly understand compromised inbox contents. Microsoft's Digital Crimes Unit emphasizes that the AI-driven model behind EvilTokens will persist, urging organizations to implement additional verification steps for transactional requests.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.