25 September 2026 — Microsoft said on 22 September it had disrupted EvilTokens, a cybercrime service that used AI to help turn access to stolen email accounts into plans for financial fraud. Microsoft links the service to more than 12,000 compromised inboxes across over 10,000 organisations worldwide since its launch in February 2026.
Key points
- Microsoft says it seized 50 websites and disabled more than 150 domains with authorisation from a US federal court.
- EvilTokens offered tools to access accounts, examine inboxes and prepare fraud through a paid Telegram service.
- UK police arrested two men on suspicion of fraud-related and money laundering offences.
Microsoft seizes 50 EvilTokens websites
Microsoft says it and its partners seized 50 websites used by EvilTokens and disabled more than 150 domains supporting the service. The work had authorisation from the US District Court for the Eastern District of Virginia, with Health-ISAC joining Microsoft’s legal action as a co-plaintiff.
Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation and TRM Labs worked with Microsoft and Health-ISAC on the disruption, Microsoft says. It says it also notified affected customers and helped secure compromised accounts.
Microsoft reports the highest concentrations of victim activity in the United States, Canada, the United Kingdom, Australia, India and France. The affected organisations worked in sectors including healthcare, construction, financial services and higher education.
EvilTokens used stolen inbox access to plan fraud
Microsoft says EvilTokens tricked victims into entering an authentication code on a legitimate Microsoft sign-in page, granting attackers access to their email without handing over a password. That access could survive a password reset if the associated sessions and tokens remained active.
Once an attacker had access, the service’s AI tools could search mail for payment discussions, identify trusted contacts and suggest people to impersonate, according to Microsoft. Its chatbot could also draft messages for a fraud attempt. The service put account access and the work of finding a suitable target in one interface.
Microsoft says EvilTokens was sold through Telegram for a $1,500 initiation fee and a recurring $500 subscription. About 1,000 cybercriminals used it during its operation, a Microsoft spokesperson told CyberScoop.
Coinbase said it traced about $1.1 million in revenue from paying customers, with more than 1,000 deposits from more than 700 distinct crypto addresses through June 2026, CyberScoop reported. Microsoft says investigators also found evidence that AI had helped the operators build large portions of EvilTokens itself.
UK police arrest two men on 18 September
The Metropolitan Police arrested Felix Utomi and Waidi Segun Adams on 18 September over suspected production of items intended for fraud and suspected money-laundering offences, CyberScoop reported. Microsoft identified the men as alleged operators of EvilTokens.
Police carried out warrants in the greater London area and seized digital devices. The two men were released on bail while the investigation continues.