Microsoft takes down AI-boosted phishing tool that hit 12,000 accounts
Two people arrested and dozens of websites seized in an organized operation against EvilTokens.
Microsoft, in collaboration with UK police and various partners, brought down the AI-enhanced phishing tool, EvilTokens PhaaS, which had infiltrated 12,000 email accounts across 10,000 organizations globally. The joint operation resulted in the arrest of two suspects and the seizure of more than 200 domains and sites. EvilTokens, a PhaaS platform operating like a startup with subscriptions and dashboards, utilized AI to scale device-code phishing attacks, compromising a significant number of inboxes.
The two arrested men, aged 32 and 38, are currently on bail pending further investigation. Victims of these attacks mainly belonged to wholesale distribution, construction, and financial services sectors, with additional targets in real estate, higher education, and healthcare. The platform offered custom-tailored phishing emails, session tokens, and one-time passwords, making it particularly dangerous due to its use of AI.
In 2026, EvilTokens experienced a 1,380% increase in device-code phishing attacks compared to the previous year, highlighting the platform's growing influence and effectiveness. Microsoft has notified affected customers and provided assistance in remediation efforts.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.