Disrupting EvilTokens: Taking down an AI-powered cybercrime platform
Microsoft disrupted EvilTokens, an AI-powered cybercrime platform used to automate email compromise and financial fraud, seizing 50 websites and arresting two suspects in the UK.
Microsoft has dismantled EvilTokens, a cybercrime platform that leveraged AI to automate email compromise and financial fraud. The service used an AI chatbot to analyze victims' inboxes, identify trusted contacts, and recommend fraud strategies, including drafting impersonation messages. EvilTokens operated as a subscription-based service sold on Telegram, combining account access, mailbox analysis, and fraud preparation into a single platform. The disruption highlights how AI is being weaponized to scale cybercrime, requiring coordinated action between industry and law enforcement.
EvilTokens compromised over 12,000 email inboxes across 10,000 organizations worldwide within months of its February 2026 launch. Affected sectors included wholesale distribution, construction, financial services, real estate, higher education, and healthcare. Microsoft seized 50 websites and disabled 150 additional domains linked to the platform’s infrastructure. The operation involved civil legal action and collaboration with partners including Cloudflare, Coinbase, OpenAI, and law enforcement agencies.
In the UK, the Metropolitan Police Service’s cybercrime team arrested two men, aged 32 and 38, on suspicion of operating EvilTokens. Both suspects were released on police bail pending further investigation. Microsoft’s Digital Crimes Unit (DCU) worked with Health-ISAC and other organizations to disrupt the platform, including notifying affected customers and remediating compromised accounts. The case underscores the importance of rapid cooperation between private-sector investigators and law enforcement.
The disruption of EvilTokens demonstrates how AI is transforming both cybercriminal tactics and defensive strategies. Microsoft’s investigation relied on reverse engineering and AI-powered tools to analyze evidence and identify supporting infrastructure. The platform’s model—combining AI with compromised accounts to accelerate fraud—remains a growing threat, as noted in Microsoft’s 2026 Responsible AI Transparency Report. Organizations are advised to strengthen identity protections and verify payment requests through trusted second channels.