Microsoft, Cloudflare and law-enforcement partners have disrupted EvilTokens, a phishing-as-a-service operation that used artificial intelligence to help criminals compromise email accounts, analyze stolen inboxes and prepare business email compromise fraud.
Microsoft said EvilTokens was linked to more than 12,000 compromised inboxes across over 10,000 organizations worldwide within months of its launch. The company said the highest concentrations of victim activity were in the United States, Canada, the United Kingdom, Australia, India and France.
AI used across the attack chain
EvilTokens combined token theft, mailbox analysis and fraud preparation in a subscription service sold through Telegram. According to Microsoft, the platform’s AI-style chatbot could inspect compromised inboxes to identify payment authorizations, trusted relationships and people responsible for moving money. It could then recommend impersonation and fraud strategies.
The service also supported device-code phishing, which abuses a legitimate authentication flow intended for devices such as smart TVs, printers and conferencing equipment. Microsoft’s technical analysis said the approach allowed attackers to obtain authentication tokens and gain access to organizational accounts while bypassing conventional multifactor-authentication protections.
Microsoft said investigators found evidence that large parts of EvilTokens had themselves been developed with AI assistance. The platform also used capabilities from multiple AI models. Access was marketed for a $1,500 initiation fee and a recurring $500 subscription, according to the company.
Domains and infrastructure taken down
Microsoft and Health-ISAC obtained authorization from the U.S. District Court for the Eastern District of Virginia to act against infrastructure supporting EvilTokens. Microsoft said it seized 50 websites used to operate the service and disabled more than 150 additional domains.
Cloudflare said its Cloudforce One team carried out a technical takedown of Workers projects and infrastructure used by the phishing service. EvilTokens customers could provide their own Cloudflare API keys to configure Workers that collected credentials and supported phishing pages, according to Cloudflare.
The operation involved Microsoft, Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation and TRM Labs. In the United Kingdom, the Metropolitan Police cybercrime team arrested two men on suspicion of offenses connected to the alleged operation of EvilTokens, Microsoft said.
Business email compromise remains the goal
The disruption illustrates how AI can be incorporated into established identity attacks rather than creating an entirely new attack method. The initial compromise still depended on phishing and abuse of authentication workflows, but EvilTokens automated parts of the process that followed access to a mailbox.
For enterprises, Microsoft’s technical guidance recommends blocking device-code authentication where it is not required and using identity and endpoint telemetry to detect suspicious sign-ins and mailbox activity. The company also published hunting queries and detection guidance for defenders.
The case follows growing scrutiny of how generative AI can lower the effort required to conduct cybercrime. In June, TNGlobal reported on Microsoft’s AI safety and security collaboration with Singapore’s IMDA, which includes information sharing, evaluation tools and work on emerging AI risks.
Featured image: Clint Patterson on Unsplash

