The AI Post
Agents & CodingOpen ModelsEnterpriseFundraisingGenerative MediaGovernanceInferenceInfrastructureLegal & SafetySector Impact
← Front Page Security · Microsoft · OpenAI · Cloudflare · Coinbase

Microsoft seizes 50 sites behind phishing kit that took 12,000 inboxes

Microsoft said EvilTokens sold device-code phishing for $1,500 and a $500 monthly fee, and that about 1,000 criminals used it before the takedown.

Microsoft said it disrupted EvilTokens, a phishing service that compromised more than 12,000 email inboxes at over 10,000 organisations worldwide. Acting on a 15 September order from the US District Court for the Eastern District of Virginia, the company and its partners seized 50 websites and disabled more than 175 domains, CyberScoop reported.

Ars Technica described EvilTokens as an end-to-end platform that makes mass compromises faster and easier. Microsoft said the service emerged in February 2026, and CyberScoop reported that about 1,000 criminals used it between then and June. Its operators charged $1,500 to buy in and $500 a month after that, according to Microsoft.

Microsoft said the kit sold AI features alongside the phishing. Assistants tailored lures and sifted through stolen mailboxes to pick out high-value targets, and the platform carried 44 email themes for building templates and landing pages. The description is Microsoft's own.

Health-ISAC, Cloudflare, OpenAI, Shadowserver, TRM Labs, SpyCloud and Coinbase joined the disruption, CyberScoop reported. UK Metropolitan Police arrested two men on 18 September in greater London on suspicion of making articles for use in fraud and money laundering. Police released both on bail.

Steven Masada, Microsoft's associate general counsel, said the takedown removed the infrastructure but not the model it demonstrated. Microsoft correlated at least 13 complaints to the FBI's Internet Crime Complaint Center with the service, worth about $1.7 million in reported losses. Coinbase traced about $1.1 million in revenue to the operators, according to CyberScoop.

Sources 3 sources

  1. Primary Microsoft Security Blog
  2. Press Ars Technica
  3. Press CyberScoop