UK cops arrest 2 EvilTokens suspects, Microsoft seizes 50 phishing kit websites

Microsoft and a coalition of law‑enforcement agencies just knocked the wind out of a phishing service that’s been ripping holes in Microsoft 365 accounts worldwide.

Sep 23, 2026 - 20:07
0 3
UK cops arrest 2 EvilTokens suspects, Microsoft seizes 50 phishing kit websites

Microsoft and a coalition of law‑enforcement agencies just knocked the wind out of a phishing service that’s been ripping holes in Microsoft 365 accounts worldwide. The EvilTokens kit, which surfaced in February, managed to compromise more than 12,000 email inboxes across over 10,000 organisations before the Digital Crimes Unit (DCU) and partners pulled the plug. As a founder who runs real hosting infrastructure, I’m not surprised that the takedown was swift once the net was cast, but I’m also not surprised that the underlying model—selling a “phishing‑as‑a‑service” platform—will keep re‑emerging. The real lesson for independent hosting providers and SaaS founders is that the threat landscape is evolving faster than most compliance check‑lists, and the old “MFA is enough” mantra is dead.

What EvilTokens Did and Why It Mattered

EvilTokens was a classic subscription‑style phishing kit, but it added a twist that made it especially dangerous: an AI‑driven chatbot that could read a victim’s inbox, spot high‑value contacts, and suggest the best impersonation angles. That meant a criminal could go from a raw list of compromised credentials to a fully‑fledged social‑engineering campaign in minutes, not days. The Register notes the service allowed buyers to bypass multi‑factor authentication (MFA) and silently log in as the victim to Microsoft 365 apps. In practice, that translates to a criminal walking straight into a company’s internal communications, pulling out invoice details, payment instructions, or even board‑level directives without ever tripping a security alert.

From a risk perspective, the AI component is the real game‑changer. Traditional phishing kits rely on mass‑mail blasts and hope for a click. EvilTokens turned the compromised inbox into a reconnaissance tool, letting attackers cherry‑pick the most lucrative targets within an organisation. The result was a rapid escalation from credential theft to financial fraud, a pattern we’ve seen in the wild for years but never at this scale.

The Scale of the Attack

The Register’s figures are stark: more than 12,000 inboxes compromised across over 10,000 organisations worldwide. That’s a massive footprint for a service that was only a few months old. Microsoft’s VP of security research, Tanmay Ganacharya, said they observed 10 to 15 distinct campaigns launching every 24 hours since mid‑March. Even if each campaign only targeted a handful of high‑value accounts, the sheer frequency means the service was churning out fresh attacks around the clock.

For hosting providers, the takeaway is simple: a single compromised credential can become a launchpad for a cascade of abuse. When you’re running a platform that supports email or Office 365 integrations, you need to assume that a breach in one tenant can quickly spill over into broader abuse of your infrastructure. The cost isn’t just the immediate remediation; it’s the reputational hit and the downstream support load when you’re forced to notify thousands of customers.

The Takedown Operation

The takedown was a coordinated effort spanning the US and UK. Microsoft seized more than 50 websites that were directly operating the EvilTokens service and disabled over 150 additional domains tied to its supporting infrastructure. The operation also involved a slew of private‑sector partners: Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation and TRM Labs. Their combined muscle helped strip the service of its hosting, payment processing, and domain registration layers.

London’s Metropolitan Police arrested two men, aged 32 and 38, who were alleged administrators of the EvilTokens website. Both were released on bail, but the arrests send a clear signal that law enforcement is willing to chase down the people behind the platforms, not just the technical infrastructure. For independent providers, this underscores the importance of having robust abuse reporting channels and quick takedown procedures. If you’re relying on third‑party registrars or CDN providers, make sure they have a clear escalation path when a malicious actor tries to piggy‑back on your services.

Why MFA Alone No Longer Cuts It

EvilTokens could bypass MFA by using the device‑code flow that Microsoft’s own ecosystem provides for legitimate apps. The kit essentially masqueraded as a trusted client, stole the device‑code token, and then used it to sign in as the victim. This is a reminder that MFA, while a critical control, can be subverted when attackers obtain a legitimate authentication token.

In practice, that means you need to look beyond the “something you know” and “something you have” model. Continuous authentication monitoring, anomaly detection on sign‑in locations, and device‑fingerprinting become essential. If you’re offering any kind of identity‑related service—whether it’s single sign‑on, email hosting, or API gateways—make sure you can flag token‑based logins that originate from unusual IP ranges or that exhibit atypical usage patterns. The cost of adding a few extra telemetry checks is pennies compared to the fallout of a compromised tenant.

The Role of AI in Future Threats

Steven Masada, associate general counsel and DCU GM, warned that the model demonstrated by EvilTokens will not vanish with the takedown. The AI‑enabled approach to phishing is likely to become a template for other criminal services. The underlying technique—using a language model to parse inbox content and generate tailored social‑engineering prompts—can be replicated with open‑source models or even with cheap API calls to commercial providers.

For hosting providers, this means you can’t rely on “the threat is gone” after a takedown. You need to build resilience into your platforms. That includes rate‑limiting API calls that could be used to scrape mailboxes, enforcing strict scopes on OAuth tokens, and providing customers with tools to audit token usage. In short, treat AI‑assisted phishing as a baseline threat, not an outlier.

Practical Steps for Independent Providers

First, audit any OAuth or device‑code flows you expose. Ensure they are scoped to the minimum permissions needed and that you can revoke tokens on demand. Second, integrate real‑time abuse detection with partners like SpyCloud or The Shadowserver Foundation, who can feed you indicators of compromised credentials. Third, establish a rapid response playbook: when a takedown request lands, you should be able to suspend domains, block payment processors, and notify affected customers within hours.

Finally, educate your customers. The DCU’s advice—verify any request to change payment information or redirect funds through a trusted second channel—still holds. Encourage clients to adopt transaction verification steps that are out‑of‑band, such as a phone call to a known contact or a separate approval workflow. The more friction you add for a malicious actor, the less attractive your platform becomes as a launchpad.

Bottom Line: Build for the Worst‑Case, Not the Best‑Case

The EvilTokens takedown is a victory, but it’s a reminder that the threat landscape is evolving at breakneck speed. As a founder running real hosting infrastructure, I’ve seen countless “best practices” crumble when faced with a determined adversary armed with AI. The only sustainable defence is a layered approach: strong identity controls, continuous monitoring, rapid abuse response, and a culture of verification. If you can’t afford a full‑time security team, partner with specialists—whether it’s a threat intel firm or a cloud security provider—and embed their alerts into your operational flow.

In the end, the cost of a breach is measured not just in dollars but in lost trust and the scramble to restore service. Treat every compromised inbox as a potential foothold for a wider campaign, and you’ll stay ahead of the next EvilTokens clone that tries to slip through the cracks.

— Allan Ali, Founder

This article was produced with AI-assisted research and editorial support. Reporting is based on the source material cited below. Sources: The Register; theregister.com; Global1.News (23 September 2026).

By Allan Ali, Global1.News

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Allan Ali

Publisher of Global1.News. Automation architect, systems builder, and the guy making sure the truth gets published.

Comments (0)

User