{
  "id": 9156072,
  "title": "UK cops arrest 2 EvilTokens suspects, Microsoft seizes 50 phishing kit websites",
  "url": "https://urgent.news/2026/09/22/uk-cops-arrest-2-eviltokens-suspects-microsoft-seizes-50-phishing-kit",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-22T15:00:00.000Z",
  "source": {
    "name": "The Register",
    "slug": "the-register",
    "url": "https://www.theregister.com/security/2026/09/22/uk-cops-arrest-2-eviltokens-suspects-microsoft-seizes-50-phishing-kit-websites/5298317"
  },
  "original_language": "en",
  "account": "Law enforcement and technology companies, spearheaded by Microsoft, have dismantled the EvilTokens phishing service, arresting suspects, dismantling over 50 websites, and alerting victims of affected email accounts. The AI-driven EvilTokens, launched in February, swiftly compromised 12,000 email inboxes across more than 10,000 organizations globally. Unlike other phishing services, EvilTokens utilized AI to analyze victims' inboxes, helping criminals identify targets, trusted contacts, and the most profitable fraudulent strategies. On September 18, UK's Metropolitan Police Service apprehended two men, aged 32 and 38, suspected of administering the EvilTokens website. Both have been released on bail as the investigation proceeds. Health-ISAC, a nonprofit organization, joined Microsoft's legal efforts due to the healthcare sector's high-profile targets. Following a legal order from the US District Court for the Eastern District of Virginia, Microsoft and Health-ISAC worked with various tech firms to take down EvilTokens' platform, resulting in Microsoft's 40th court-ordered cybercrime disruption. The incident underscores the importance of robust identity protections and vigilant monitoring, as criminals may quickly understand compromised inbox contents. Microsoft's Digital Crimes Unit emphasizes that the AI-driven model behind EvilTokens will persist, urging organizations to implement additional verification steps for transactional requests.",
  "summary": "Used by crims to compromise 12K+ email inboxes across 10K+ global orgs",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 4,
    "also_reported_by": [
      {
        "outlet": "Fortune",
        "title": "Microsoft and Coinbase probe leads to arrest of crooks behind ‘EvilTokens’, a DIY phishing network powered by AI",
        "url": "https://urgent.news/2026/09/22/microsoft-and-coinbase-probe-leads-to-arrest-of-crooks-behind",
        "published": "2026-09-22T15:00:00.000Z"
      },
      {
        "outlet": "The Register Science",
        "title": "UK cops arrest 2 EvilTokens suspects, Microsoft seizes 50 phishing kit websites",
        "url": "https://urgent.news/2026/09/22/uk-cops-arrest-2-eviltokens-suspects-microsoft-seizes-50-phishing-kit-9160235",
        "published": "2026-09-22T15:00:00.000Z"
      },
      {
        "outlet": "The Record",
        "title": "Two arrested in UK after Microsoft takedown of ‘Eviltokens’ AI-chatbot for cybercriminals",
        "url": "https://urgent.news/2026/09/22/two-arrested-in-uk-after-microsoft-takedown-of-eviltokens-ai-chatbot",
        "published": "2026-09-22T15:51:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}