Security News

Microsoft and UK Police Take Down 'EvilTokens' AI-Powered Phishing Service

The Register · 23 Sept 2026
Key Takeaway Enable phishing-resistant multi-factor authentication and train staff to spot suspicious login prompts, since even MFA can be bypassed by sophisticated phishing kits like EvilTokens.

Microsoft, working with UK law enforcement, has dismantled a phishing service known as EvilTokens, seizing more than 50 websites and disabling over 150 supporting domains. The service, which emerged in February, was used by criminals to compromise more than 12,000 email inboxes across over 10,000 organisations globally.

EvilTokens was sold as a subscription tool that let buyers bypass multi-factor authentication and quietly log in to victims' Microsoft 365 accounts as if they were the legitimate user. Unusually, the kit included an AI chatbot that could scan a victim's inbox to identify high-value targets, suggest which trusted contacts to impersonate, and recommend fraud tactics to maximise payouts for attackers. Microsoft reported observing 10 to 15 distinct campaigns launching every day as the operation scaled.

London's Metropolitan Police arrested two men, aged 32 and 38, on suspicion of administering the EvilTokens website; both have been released on bail as the investigation continues. Because healthcare organisations were among the victims, the nonprofit Health-ISAC joined Microsoft's legal action as a co-plaintiff.

Summarised by CISO AI from The Register. We link back to every original so you can read it yourself.