Skip to content
Microsoft Dismantles EvilTokens AI Phishing Service, Two Arrested

Microsoft Dismantles EvilTokens AI Phishing Service, Two Arrested

First seen 22 Sep 2026, 18:33 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 22, 2026 at 19:25 UTC
  • Microsoft dismantled the EvilTokens phishing service using AI for cybercrime.
  • Two suspects were arrested in the U.K. as part of the operation.
  • EvilTokens offered a subscription model for phishing tools, lowering the expertise needed for attacks.

Microsoft has taken down the EvilTokens phishing service, which utilized AI to assist cybercriminals in compromising email accounts and executing financial fraud. The takedown was authorized by the U.S. District Court for the Eastern District of Virginia and involved collaboration with Health-ISAC, Cloudflare, and others. Two men, aged 32 and 38, were arrested by the Metropolitan Police Service in the U.K. on September 11, 2026, in connection with the operation. EvilTokens operated as a phishing-as-a-service platform, charging $1,500 for initiation and $500 monthly, and provided tools for analyzing breached inboxes and automating fraud strategies. The platform's AI capabilities allowed it to identify trusted relationships and suggest fraud tactics, significantly lowering the barrier for cybercriminals. Microsoft has been tracking the threat actors, referred to as Storm-2992. The service was first reported by Huntress in March 2026 and has been characterized as a comprehensive tool for business email compromise and invoice fraud.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-03-01
EvilTokens first documented
Huntress reported on EvilTokens as a phishing-as-a-service platform abusing OAuth 2.0.
The Hacker News
2026-09-11
Two arrests made in U.K.
Metropolitan Police arrested two men, aged 32 and 38, linked to EvilTokens operation.
Therecord.Media
2026-09-22
Microsoft announces takedown
Microsoft revealed the takedown of EvilTokens and its AI-driven capabilities.
The Hacker News

More articles in this cluster (3)

Following this threat?

Track Storm-2992, Amadey and Cloudflare in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed