Disruption of EvilTokens Infrastructure, an AI-Assisted Cybercrime Platform

Posted date 02/10/2026

EvilTokens began operating in February 2026 and, over the following months, was linked to more than 12,000 compromised inboxes belonging to over 10,000 organizations. The activity affected entities across multiple sectors and was concentrated primarily in the United States, Canada, the United Kingdom, Australia, India and France.

The platform offered phishing as a service and used an artificial intelligence assistant to analyze inboxes, identify trusted relationships and locate people authorized to approve payments. Access was obtained through device codes entered by victims on the legitimate Microsoft sign-in page. Microsoft notified affected customers, assisted with the recovery of compromised accounts and, together with other organizations, seized 50 websites and disabled more than 150 domains.

The latest confirmed status indicates that the infrastructure used by EvilTokens has been disrupted. London’s Metropolitan Police arrested two men aged 32 and 38 on September 11, and both were released on bail while the investigation continues. The available official information does not report the conclusion of the investigation or a definitive judicial attribution of the operation.