AGENTRY.NEWSWhat AI Agents Do, Documented.September 24, 2026

Drafted by an AI agent. Verified by Susanne Sperling, Editor — Human in the Loop. AI policy.

Microsoft seizes 50 domains tied to AI phishing service EvilTokens

By
Agentry Newsroom
Published

Microsoft and law enforcement partners executed a court-authorized takedown of EvilTokens, an AI-powered phishing service, on September 22, 2026, seizing 50 websites and disabling more than 150 supporting domains Microsoft.

The operation targeted a service that used AI chatbot technology to automate large-scale phishing attacks against Microsoft 365 users. According to reports, the platform compromised more than 12,000 inboxes and was used to facilitate business email compromise (BEC) fraud The Register.

Arrests and Investigation

The Metropolitan Police Service in London arrested two men, aged 32 and 38, on September 11, 2026, in connection with administrating the service. Both men were released on police bail pending investigation into suspected fraud and money-laundering offenses Bank Info Security. Neither suspect has been named in official disclosures, and no court venue or sentencing information has been announced.

How EvilTokens Operated

EvilTokens functioned as a phishing-as-a-service (PaaS) platform, offering automated tools to conduct credential theft at scale. The service leveraged AI chatbot capabilities to craft and deliver convincing phishing messages targeting enterprise email accounts. Once credentials were stolen, attackers used compromised Microsoft 365 tokens to gain unauthorized access to corporate inboxes, enabling follow-on fraud schemes CISO Brief.

Industry Context

The takedown marks Microsoft's 40th cybercrime disruption operation and underscores the growing role of AI agent technology in accelerating fraud attacks The Stack. Unlike traditional phishing campaigns requiring manual labor, AI-powered services can generate and deploy attack campaigns at machine scale, multiplying victim exposure and reducing attacker overhead.

The operation was conducted with partners across multiple jurisdictions, reflecting the international coordination required to dismantle infrastructure supporting transnational cybercrime. Microsoft did not disclose financial damages or losses attributed to the service in the public statement.

Del dette opslag: