“Since March 15, 2026, we have observed 10 to 15 distinct campaigns launching every 24 hours,” Microsoft VP of security research Tanmay Ganacharya told The Register in an earlier interview about the phishing service.
EvilTokens: an AI‑enabled device‑code phishing service and its reach
EvilTokens emerged in February as a Microsoft device-code phishing kit sold as-a-service, and within months had been used to compromise 12,000 email inboxes across more than 10,000 organizations worldwide. Beyond the usual mechanics for bypassing multi‑factor authentication (MFA) and silently authenticating as a victim to Microsoft 365 applications, the kit included an AI chatbot that could analyse a victim’s inbox, help criminals identify profitable targets, and suggest which trusted contacts to impersonate and which fraud strategies to use.
Coordinated legal and technical disruption led by Microsoft and Health‑ISAC
Late last week, Microsoft and nonprofit Health‑ISAC obtained authorizations from the US District Court for the Eastern District of Virginia and moved to disrupt the platform. Microsoft’s Digital Crimes Unit (DCU), acting with Health‑ISAC as a co‑plaintiff, seized 50 websites used to operate EvilTokens and disabled more than 150 additional domains tied to its supporting infrastructure. Microsoft also notified affected customers and helped remediate compromised accounts.
The action represents the DCU’s 40th court‑authorized disruption over nearly two decades and, according to Steven Masada, associate general counsel and DCU GM, is the DCU’s first action against an end‑to‑end AI‑enabled cybercrime service. “The infrastructure supporting EvilTokens has been disrupted, but the model it demonstrated will not disappear with it,” Masada said in a blog shared with The Register ahead of publication.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scramblePrivate‑sector partners and platform providers in the takedown
Microsoft and Health‑ISAC worked with a coalition of tech companies to execute the takedown. The organizations named in the legal action and operational effort include Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation and TRM Labs. The combined court authorization and technical cooperation allowed the parties to seize domains and take down platform elements tied to EvilTokens’ operation.
Metropolitan Police investigation and arrests in London
On September 18, London’s Metropolitan Police Service arrested two men, aged 32 and 38, who allegedly acted as the administrators of the EvilTokens website. Both men have been released on bail while the Met’s investigation continues. Detective Inspector Serena D'Adamo, whose team led the Met's inquiry, said in an emailed statement to The Register: “Phishing services bring misery to thousands, taking money from everyday people across the world. The Met remains committed to holding people to account who facilitate criminal enabling functions and think they can remain undetected.”
What this means for Microsoft, Health‑ISAC, and affected organizations
- Microsoft DCU: The takedown marks a milestone in the unit’s disruption toolkit — a court‑authorized action against an AI‑enabled service — and signals continued reliance on legal process plus cross‑sector technical cooperation. Microsoft has already notified and helped affected customers remediate compromised accounts.
- Health‑ISAC and healthcare organizations: Because healthcare entities were among those targeted, Health‑ISAC joined the legal action as a co‑plaintiff; affected health organizations will need to follow remediation guidance and monitor for follow‑on fraud tied to compromised inboxes.
- Affected enterprises and security teams: The DCU’s public guidance underscores that criminals may understand inbox contents “in minutes, not days,” reinforcing the need to verify requests to change payment information or approve unusual transactions through a trusted second channel, in addition to strong identity protections and monitoring.
The coordinated takedown removed infrastructure and arrested alleged administrators, but key actors in the operation warned by Microsoft and the DCU remain that the underlying model — an accessible, AI‑assisted phishing-as-a-service — can be replicated. As Masada put it, “The infrastructure supporting EvilTokens has been disrupted, but the model it demonstrated will not disappear with it.” The case now proceeds as law enforcement continues its investigation and affected organizations complete remediation and notification steps.




