Home Technology UK cops arrest 2 EvilTokens suspects, Microsoft seizes...
Technology

UK cops arrest 2 EvilTokens suspects, Microsoft seizes 50 phishing kit websites

UK cops arrest 2 EvilTokens suspects, Microsoft seizes 50 phishing kit websites
Key Points

A coalition of law enforcement and private-sector tech companies led by Microsoft have disrupted the EvilTokens phishing service, arresting suspected website admins, taking down more than 50 websites, and notifying victims of compromised email accounts. EvilTokens is a notorious Microsoft device-code phishing kit that emerged in February, and, within months of launching, had been used by criminals to compromise 12,000 email inboxes across more than 10,000 organizations worldwide. Like other...

A coalition of law enforcement and private-sector tech companies led by Microsoft have disrupted the EvilTokens phishing service, arresting suspected website admins, taking down more than 50 websites, and notifying victims of compromised email accounts. EvilTokens is a notorious Microsoft device-code phishing kit that emerged in February, and, within months of launching, had been used by criminals to compromise 12,000 email inboxes across more than 10,000 organizations worldwide. Like other similar phishing subscriptions, EvilTokens was sold as-a-service, and allowed buyers to bypass multi-factor authentication (MFA) and silently authenticate as the victim to the organization's Microsoft 365 applications. What made this one especially insidious, however, was its AI use. EvilTokens featured an AI chatbot that could analyze a victim’s inbox, and help criminals identify who to target, which trusted contacts to impersonate, and even which fraud strategies to use to maximize criminals’ paydays. “Since March 15, 2026, we have observed 10 to 15 distinct campaigns launching every 24 hours," Microsoft VP of security research Tanmay Ganacharya told The Register in an earlier interview about the phishing service. Late last week, in a coordinated effort that spanned the US and UK, Microsoft seized 50 websites used to operate the service and disabled more than 150 additional domains tied to its supporting infrastructure. Meanwhile, London’s Metropolitan Police Service on September 18 arrested two men, aged 32 and 38, who allegedly acted as the administrators of the EvilTokens website. Both men have been released on bail while the investigation continues. “Phishing services bring misery to thousands, taking money from everyday people across the world,” Detective Inspector Serena D'Adamo, whose team led the Met's investigation, told The Register in an emailed statement. “The Met remains committed to holding people to account who facilitate criminal enabling functions and think they can remain undetected.” Because healthcare organizations were among those targeted, Health-ISAC, a nonprofit that helps health sector organizations share cyber-threat information, joined Microsoft’s legal action as a co-plaintiff. After receiving authorizations from the US District Court for the Eastern District of Virginia, Microsoft and Health-ISAC worked with Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation and TRM Labs, took down EvilTokens’ platform, and Microsoft notified affected customers, helping them remediate compromised accounts. This action marks the Microsoft Digital Crimes Unit’s (DCU) 40th court-authorized disruption over nearly two decades. According to Steven Masada, associate general counsel and DCU GM, this is also DCU’s first action against an end-to-end AI-enabled cybercrime service. “The infrastructure supporting EvilTokens has been disrupted, but the model it demonstrated will not disappear with it,” he said in a blog shared with The Register ahead of publication. “For organizations, the lesson is: assume that once an inbox is compromised, criminals may understand its contents in minutes, not days. Strong identity protections and monitoring remain essential, but organizations should also independently verify requests to change payment information, redirect funds or approve unusual transactions through a trusted second channel.” ®
UK (LOCATION) EvilTokens (ORG) Microsoft (ORG) MFA (ORG) AI (ORG) Microsoft VP (ORG) Tanmay Ganacharya (PERSON) Register (ORG) US (LOCATION) London (LOCATION) Metropolitan Police Service (ORG) Serena D'Adamo (PERSON) the US District Court (ORG) the Eastern District (LOCATION) Virginia (LOCATION)
Originally published by The Register Read original →