Friday, 9 October 2026 SourcesAbout🌓
🇬🇧 UK ▾
BREAKING
Technology

Microsoft takes down AI-boosted phishing tool that hit 12,000 accounts

TechRadar ·
Microsoft takes down AI-boosted phishing tool that hit 12,000 accounts

Microsoft, UK police, and partners disrupted EvilTokens PhaaS, arresting two suspects and seizing 200+ domains/sites EvilTokens used AI to scale device‑code phishing, compromising 12,000 inboxes across 10,000 organizations globally Platform ran like a startup with subscriptions, dashboards, and AI‑driven targeting; US victims hit hardest Two people have been arrested, 50 websites were seized, and 150 domains disabled, in a joint operation against the infamous EvilTokens phishing-as-a-service (PhaaS) kit.

In its report , Microsoft said the UK Metropolitan Police Service’s cybercrime team “arrested two men on suspicion of offenses connected with the alleged operation of EvilTokens.” The two men, whose identities were not disclosed, are aged 32 and 38, and have been released on bail, subject to conditions while the investigation continues.

Their digital services and other items have been confiscated, as well.

Among the partners are Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs.

We don’t know if these arrests and takedowns will be enough to completely obliterate EvilTokens, or if the platform will continue to operate.

Usually, criminal infrastructure is a lot less resilient to disruptions when arrests are made, compared to when law enforcement simply disables the hardware.

The tech startup of organized crime EvilTokens has been turning heads for a little while now.

The platform was first spotted in February 2026, rising quickly to become one of the most widely used PhaaS solutions out there.

It can be bought through Telegram for $1,500, after which there is a recurring $500 subscription cost.

Cybercriminals use it to run large-scale, personalized phishing attacks: they can create spoofed websites, landing pages, and other credential-capture assets; they can create custom-tailored phishing emails, and can even grab session tokens, one-time passwords , and other codes designed to protect accounts against phishing, granting attackers access to people’s inboxes.

But what makes EvilTokens particularly impressive is its use of artificial intelligence.

The platform comes with an AI assistant that can sift through the inboxes, suggest which targets are of high value, and even how to approach them.

Attackers can conduct Microsoft Graph reconnaissance as well, mapping out organizational structure and permissions, keeping access and moving laterally throughout the target network.

Microsoft said it found evidence of large portions of EvilTokens being vibe coded, “with AI helping its creators build the platform itself.” The researchers also found the platform drawing on capabilities from multiple AI models.

Read the full article on TechRadar ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.

More from TechRadar

See all ›

More in Technology

See all ›