Skip to main content
Emerging ThreatsMalware & Ransomware

Microsoft Disrupts EvilTokens Cybercrime Service

Network operations center with computer equipment and cables, lit by natural daylight from large windows.

"AI was not simply helping attackers write more convincing messages. It helped them decide who to target, who to impersonate, and how to most effectively exploit the relationship to extract as much money as possible," Steven Masada wrote in a Microsoft blog post.

How Microsoft and partners dismantled EvilTokens

Acting on a federal court order on Sept. 15, Microsoft and a coalition of industry partners seized 50 websites used by EvilTokens and disabled more than 175 domains tied to its supporting infrastructure, the company said. Partners named in Microsoft’s account of the takedown include Health-ISAC, Cloudflare, OpenAI, Shadowserver and TRM Labs; Coinbase and SpyCloud also aided the investigation. The companies identified and notified potential victims, shared indicators of compromise, and provided intelligence to law enforcement.

EvilTokens’ AI-driven attack chain

Launched in February 2026, EvilTokens presented itself as a phishing-as-a-service platform that integrated AI across the attack lifecycle. Central to the service was an AI-style chatbot which users employed to analyze victims’ inboxes, identify trusted relationships and payment authorizations, and produce "intricate roadmaps for financial fraud and scams," Microsoft said. The platform used stolen session tokens to sift through inboxes and maintain persistent access, enabling attackers to bypass multi-factor authentication, email gateways and endpoint security protections. Microsoft also said the service allowed mapping of organizational structure and permissions via Microsoft Graph to facilitate lateral movement.

Monetization, scale and reported losses

Microsoft linked EvilTokens to more than 12,000 compromised Microsoft customer email inboxes across over 10,000 organizations worldwide. SpyCloud identified compromised email domains spanning 79 countries. About 1,000 cybercriminals used the service during its operation, according to a Microsoft spokesperson quoted by CyberScoop.

The platform operated on a commercial subscription model sold through Telegram: a $1,500 initiation fee and a recurring $500 subscription. Coinbase traced roughly $1.1 million in revenue to EvilTokens from customer deposits, identifying more than 1,000 deposits from over 700 distinct addresses through June 2026. Microsoft told CyberScoop it correlated at least 13 complaints filed with the FBI’s Internet Crime Complaint Center to EvilTokens-linked activity, representing approximately $1.7 million in reported losses — a figure the company calls a conservative estimate because many incidents go unreported or cannot be definitively linked to specific campaigns.

Law enforcement actions in the United Kingdom and U.S. filings

Microsoft said it identified two men — Felix Utomi and Waidi Segun Adams — and attributed the development and support of the platform to a threat actor it called Storm-2992. The Metropolitan Police served warrants in the greater London area on Sept. 18, arrested the two men on allegations tied to making articles for use in fraud and money laundering, and seized their digital devices. The Metropolitan Police said it received information from Microsoft about EvilTokens’ administrators in August; Utomi and Adams were released on bail while the investigation continues.

Microsoft’s legal filing in the U.S. District Court for the Eastern District of Virginia also references five additional unidentified people alleged to have acted as support personnel and users.

How technologists, procurement leaders, and end users should respond

  • Technologists and security teams: Microsoft and partners shared indicators of compromise and urged defenders to treat unsolicited device codes as a red flag and to assume that a compromised account can be cataloged in minutes. The service’s ability to map permissions in Microsoft Graph and to use active tokens to bypass controls underscores the need to monitor token use and unexpected lateral movement.
  • Procurement and enterprise leaders: The takedown highlights how commercially operated criminal services can package complex identity, cloud, social engineering and financial-fraud tools into a single subscription — a factor to weigh when assessing vendor and cloud-account security and incident response readiness.
  • End users and finance teams: Experts advised independently verifying any requests to change payment information or redirect funds, and to treat unsolicited authentication codes as possible indicators of ongoing targeted compromise.

Microsoft and its partners disrupted the infrastructure behind EvilTokens and provided law enforcement with leads that produced arrests and seized devices, but company officials warned the model of a subscription-run, AI-enabled fraud service will not disappear with this single takedown. Investigations and intelligence sharing continue as authorities and defenders work to trace further abuse and to reduce the opportunity such platforms provide to would-be fraudsters.

https://cyberscoop.com/microsoft-eviltokens-cybercrime-service-takedown/