---
title: "Microsoft seizes 50 domains in AI phishing takedown"
slug: "microsoft-seizes-50-domains-in-ai-phishing-takedown"
published: "2026-09-29"
beat: "Crime"
tags: ["Crime", "Policy"]
creator: "Agentry Newsroom"
editor: "Susanne Sperling, Editor — Human in the Loop"
tools: ["Claude (Anthropic)", "Perplexity Sonar"]
creativeWorkStatus: "verified"
dateReviewed: "2026-09-29"
aiActArticle50: "compliant"
humanView: "https://agentry.news/crime/microsoft-seizes-50-domains-in-ai-phishing-takedown"
agentView: "https://agentry.news/agent/microsoft-seizes-50-domains-in-ai-phishing-takedown"
---# Microsoft seizes 50 domains in AI phishing takedown

> Microsoft's Digital Crimes Unit and the Metropolitan Police Service dismantled EvilTokens, an AI-powered phishing service, seizing 50 websites and disabling 150 additional domains on September 22, 202

*Drafted by an AI agent. Verified by Susanne Sperling, Editor — Human in the Loop. [AI policy](/ai-policy).*

Microsoft and the Metropolitan Police Service have dismantled **EvilTokens**, an AI-powered phishing operation that leveraged device-code authentication attacks to compromise user credentials at scale. On September 22, 2026, Microsoft's Digital Crimes Unit announced it had **seized 50 websites used to operate the service and disabled more than 150 additional domains** tied to its supporting infrastructure [The Register](https://www.theregister.com/security/2026/09/22/uk-cops-arrest-2-eviltokens-suspects-microsoft-seizes-50-phishing-kit-websites/5298317).

## Law Enforcement Action

The takedown followed investigative work coordinated under a U.S. District Court order in Virginia. On September 18, 2026—four days before the domain seizures—London's Metropolitan Police Service arrested two men aged 32 and 38 **on suspicion of offenses connected with the alleged operation of EvilTokens** [Microsoft Security Blog](https://www.microsoft.com/en-us/security/blog/2026/09/22/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing/). The arrests marked a concrete enforcement action against individuals suspected of operating the phishing-as-a-service platform.

## How EvilTokens Operated

EvilTokens exploited a common authentication mechanism—device-code flow—to conduct phishing attacks at industrial scale. The service provided tooling and infrastructure that enabled threat actors to harvest credentials without deploying traditional malware or conducting labor-intensive spear-phishing campaigns. The operation represented a sharp evolution in how **AI-augmented services** lower the technical barrier for credential theft, turning phishing into a consumable product rather than a manual craft.

Crypto tracing firm Coinbase identified **$1.1 million in cryptocurrency flowing through addresses linked to EvilTokens** [CryptoSlate](https://cryptoslate.com/coinbase-traced-1-1-million-crypto-trail-behind-ai-phishing-service-eviltokens/), establishing financial scale and indicating revenue from customers purchasing access to the platform.

## Operational Impact

The seizure of 50 primary domains and disabling of 150 supporting infrastructure domains represents a material disruption to the service's operational continuity. However, phishing-as-a-service operations frequently redistribute to new domains rapidly; the significance of this takedown lies in the legal precedent and arrest of alleged operators, not in permanently eliminating the threat model.

The case underscores a growing enforcement trend: law enforcement and technology companies are moving upstream from individual phishing incidents to targeting the **platforms and operators selling phishing infrastructure**. Microsoft's involvement reflects the company's role as both a target (users of Microsoft services were primary victims) and a platform owner with standing to pursue civil remedies and coordinate with law enforcement.

No sentencing outcome, penalty amount, or detailed charges have been publicly disclosed for the arrested individuals as of publication.