Microsoft has helped dismantle an AI-powered phishing operation that turned artificial intelligence into a tool for large-scale business email compromise.
The operation, known as EvilTokens, used AI to help cybercriminals analyse compromised inboxes, identify valuable targets and create personalised phishing and fraud messages.
According to Microsoft, the platform was linked to approximately 12,000 compromised inboxes across more than 10,000 organisations worldwide. The victims included organisations in sectors such as healthcare, financial services, construction, real estate and higher education.
The disruption involved Microsoft, Health-ISAC, Cloudflare, Coinbase, OpenAI, SpyCloud, the Shadowserver Foundation, TRM Labs and law enforcement partners.
How EvilTokens Used AI to Scale Phishing
EvilTokens was not simply a collection of phishing templates.
Microsoft says the platform used AI throughout the attack process.
The system could help criminals:
- Identify high-value targets
- Analyse compromised email inboxes
- Find trusted relationships
- Identify payment approval processes
- Decide who to impersonate
- Create personalised social engineering messages
- Prepare business email compromise campaigns
This allowed attackers to automate tasks that would previously have required substantial manual research.
Microsoft said the platform’s AI chatbot could analyse information inside compromised mailboxes and recommend strategies for extracting money through impersonation and fraud.
EvilTokens Made MFA Phishing Easier
One of the notable elements of the operation was its use of device-code authentication.
Device-code authentication is a legitimate method designed for devices where entering credentials directly can be difficult.
EvilTokens abused this process by directing victims to authenticate an attacker-controlled device through a legitimate Microsoft login flow.
Once a victim followed the instructions, attackers could obtain access to the account without needing the user’s password.
This helped EvilTokens bypass some traditional phishing defences and gain persistent access to Microsoft 365 environments.
Microsoft Takes Legal Action
Microsoft’s Digital Crimes Unit worked with Health-ISAC and other partners to disrupt the infrastructure supporting EvilTokens.
With authorisation from the U.S. District Court for the Eastern District of Virginia, Microsoft and its partners acted against websites and domains connected to the operation.
Microsoft says it seized 50 websites and disabled another 150 domains associated with EvilTokens.
The action was designed to cut attackers off from the infrastructure they used to operate the service and help organisations identify and respond to affected accounts.
Two Suspects Arrested in the UK
The operation also involved law enforcement action in the United Kingdom.
Microsoft says its investigators shared intelligence with the Metropolitan Police Service’s cybercrime team.
On September 11, UK officers arrested two men, aged 32 and 38, and seized digital devices and other items for examination. The arrests are part of the continuing investigation.
The Economics of AI-Powered Cybercrime
EvilTokens demonstrates another important development in the cybercrime economy.
Criminals increasingly do not need to build every component of an attack themselves.
Instead, cybercrime platforms can package complex capabilities into subscription-based services.
According to Microsoft and security researchers, EvilTokens was offered to criminals for an initial $1,500 payment followed by a $500 monthly subscription.
AI adds another layer to this model.
By automating research, target selection and message generation, attackers can potentially conduct more personalised campaigns without increasing their manual workload at the same rate.
AI Is Changing the Phishing Threat
Traditional phishing often relies on generic messages containing obvious spelling mistakes, suspicious links or poorly targeted requests.
Generative AI makes it easier to create convincing messages tailored to specific people and organisations.
That does not mean every AI-generated phishing campaign will succeed. But the technology can lower the effort required to produce personalised social engineering content at scale.
Microsoft’s own threat research describes cyberattackers increasingly using AI and agents to automate activities that previously required much larger teams.
A Wider Industry Response
Microsoft’s EvilTokens disruption also highlights the growing importance of cooperation between technology companies, cybersecurity firms and law enforcement.
The operation involved organisations across different parts of the technology and security ecosystem.
That cooperation matters because modern phishing infrastructure can span:
- Cloud services
- Domain registrars
- Identity platforms
- Cryptocurrency networks
- Email infrastructure
- Compromised accounts
- Criminal marketplaces
Taking down one component may not be enough. Disrupting the broader infrastructure can make it significantly harder for attackers to continue operating.
What Businesses Can Learn
The EvilTokens case is a reminder that organisations need to look beyond traditional password protection.
Businesses should pay particular attention to:
- Phishing-resistant authentication
- Device-code authentication abuse
- Unusual login activity
- Suspicious OAuth activity
- Business email compromise
- Unusual mailbox access
- AI-generated social engineering
- Employee security awareness
Security teams also need to assume that phishing messages can increasingly be personalised and grammatically convincing.
Final Thoughts
The disruption of EvilTokens shows how artificial intelligence is becoming part of both sides of the cybersecurity battle.
Attackers are using AI to automate reconnaissance, analyse stolen information and create more convincing social engineering campaigns.
Defenders, meanwhile, are using AI to identify threats, connect investigations and disrupt criminal infrastructure.
Microsoft’s action against EvilTokens demonstrates that combating AI-enabled cybercrime will require more than better phishing filters. It will increasingly depend on cooperation between technology companies, security researchers and law enforcement.
As AI lowers the cost of sophisticated cybercrime, the ability to detect and disrupt these operations quickly is becoming increasingly important.
- Microsoft Dismantles AI-Powered Phishing Operation That Hit 10,000 Organisations - September 24, 2026
- Apple’s New Siri AI Rolls Out to Millions of iPhones With iOS 27 - September 15, 2026
- Meta Muse AI Agent: Meet the Personal AI That Gets Things Done - September 9, 2026



