Microsoft-led operation dismantles phishing service that breached thousands of accounts

Microsoft's Digital Crimes Unit coordinated a takedown of the EvilTokens phishing-as-a-service platform, which had compromised over 12,000 Microsoft accounts across more than 10,000 organizations. The service specialized in device-code phishing and offered AI-powered tools for crafting lures and scanning inboxes for high-value targets. Two suspects arrested in the U.K. were released on bail as the investigation continues.
The EvilTokens service operated on a subscription model, charging $500 monthly or a $1,500 one-time fee, with additional tools sold separately, including anti-bot redirectors and email-sending utilities. Subscribers could choose from 44 customizable phishing kits that impersonated document-signing platforms, invoicing systems, and Microsoft services, with lures ranging from construction bids to password-expiration warnings. After compromising an account, the platform leveraged Microsoft Graph to map organizational connections and used AI to scan mailbox contents for high-value targets. SpyCloud recovered data showing over 8,700 compromised accounts spanning 6,585 corporate domains across 79 countries, while the two arrested suspects, aged 32 and 38, were released on bail following warrants executed in Canary Wharf and Nine Elms.
This takedown may signal a shift in how law enforcement addresses the growing commodification of cybercrime, where platforms like EvilTokens lower the technical barrier for attackers. Organizations relying solely on standard MFA could face continued risk, as device-code phishing exploits legitimate authentication flows that many security teams may not fully monitor. The AI-powered targeting features may also accelerate the sophistication of business email compromise, potentially affecting financial losses and data exposure across sectors like healthcare and construction.