Microsoft has dismantled the EvilTokens phishing service, a sophisticated operation leveraging artificial intelligence (AI) to orchestrate widespread email compromises. This takedown, announced on Tuesday, was executed with the aid of multiple partners, including Health-ISAC and Cloudflare. The initiative received legal backing from the U.S. District Court for the Eastern District of Virginia.
Operation Details and Arrests
The coordinated action against EvilTokens involved various partners and resulted in the arrest of two individuals in mid-September. These arrests were part of a broader strategy to dismantle what Microsoft described as a formidable cybercrime platform. Utilizing AI, EvilTokens helped cybercriminals analyze email accounts to identify opportunities for financial fraud and scams.
According to Steven Masada, a key official at Microsoft’s Digital Crimes Unit, the platform’s AI capabilities allowed criminals to understand victim relationships and devise fraudulent activities. This service was not only about account takeovers but also included AI-driven email analysis and fraud strategy development.
Phishing as a Service Model
Initially documented by Huntress in early 2026, EvilTokens operated under a phishing-as-a-service (PhaaS) model. It exploited OAuth 2.0 device authorization to access victim accounts invisibly. The service facilitated email data theft and allowed attackers to maintain access by setting deceptive inbox rules.
The service’s offerings included several products, such as the Office 365 capture link, which allowed affiliates to access Microsoft tokens for a fee. These features enabled attackers to personalize phishing lures and utilize AI to craft convincing phishing emails.
Impact and Future Security Measures
Microsoft’s data indicates that EvilTokens has compromised over 12,000 email inboxes globally, affecting organizations across various sectors. The geographical spread of victims includes countries like the U.S., Canada, and the U.K., among others. Targeted sectors range from finance to healthcare and education.
In collaboration with partners, Microsoft has deactivated 50 websites and over 150 domains linked to EvilTokens. This move is part of broader efforts to disrupt similar phishing services. SpyCloud, a partner in the operation, provided intelligence on compromised accounts, highlighting the extensive reach of EvilTokens.
While the dismantling of EvilTokens marks a significant step in combating phishing, it underscores the need for continued vigilance in cybersecurity. Microsoft’s intervention demonstrates the importance of collaborative efforts in tackling sophisticated cyber threats. As technology evolves, security measures must adapt to prevent similar threats in the future.
