Two men have been arrested in the United Kingdom following a Microsoft-led legal and technical takedown of "EvilTokens," an AI-powered chatbot service that gave cybercriminals an off-the-shelf toolkit for compromising email accounts and running fraud campaigns. The Microsoft Digital Crimes Unit (DCU) says the action — its 40th court-authorized disruption in nearly two decades — is the company's first against what it calls an "end-to-end AI-enabled cybercrime service."
How EvilTokens Worked
EvilTokens was sold as a subscription product, distributed and marketed through Telegram for a $1,500 initiation fee plus a recurring $500 monthly subscription. Microsoft estimates roughly 1,000 cybercriminals used the service after it emerged in February 2026, and within months it had been linked to more than 12,000 compromised email inboxes across over 10,000 organizations worldwide, with the heaviest concentrations of victims in the United States, Canada, the UK, Australia, India, and France.
At the center of the service was an AI chatbot that automated much of the work traditionally requiring specialized skills across identity attacks, cloud systems, social engineering, and financial fraud. According to Microsoft, the chatbot could:
- Compromise accounts by abusing Microsoft's OAuth 2.0 device-code authentication flow — a device-code phishing technique that tricked victims into entering a short-lived authentication code on the legitimate Microsoft login page, handing attackers a valid session token without ever exposing a password.
- Analyze breached inboxes at scale, summarizing message contents and mapping organizational roles and reporting lines.
- Identify trusted relationships, payment authorizations, and other circumstances where fraud was most likely to succeed.
- Recommend fraud strategies and draft personalized, convincing messages that impersonated trusted contacts to manipulate victims into acting.
In effect, EvilTokens combined account compromise, mailbox analysis, target selection, and fraud preparation into a single guided interface — collapsing what once took a team of specialists into a service anyone with $1,500 could subscribe to.
The Takedown and the Arrests
Microsoft's DCU partnered with the health-sector cybersecurity nonprofit Health-ISAC on a civil lawsuit filed in the U.S. District Court for the Eastern District of Virginia, obtaining court authorization to dismantle the platform's infrastructure. Acting on that authorization, Microsoft seized 50 websites used to operate EvilTokens and disabled more than 150 additional supporting domains. Steven Masada, associate general counsel for the Microsoft DCU, led the legal effort, which drew support from Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs. SpyCloud's analysis of compromised data tied to the operation identified affected email domains spanning 79 countries.
On the law enforcement side, Microsoft shared intelligence with the Metropolitan Police Service's cybercrime team, which had received information about the suspects in August. On September 11, 2026, officers executed warrants at addresses in Canary Wharf and Nine Elms, arresting two men, aged 32 and 38, and seizing digital devices and other items for examination. Both men have been released on police bail subject to conditions while the investigation continues. Microsoft has publicly identified the pair as Felix Utomi and Waidi Segun Adams, and attributes development and support of the platform to a threat actor it tracks as Storm-2992, which it says is unaffiliated with any other known cybercrime group.
Detective Inspector Serena D'Adamo of the Metropolitan Police said phishing services "bring misery to thousands, taking money from everyday people," while a Met Police spokesperson added that the force "remains committed to holding people to account who facilitate criminal enabling functions and think they can remain undetected."
Why This Matters
EvilTokens is a stark illustration of how generative AI is lowering the skill floor for cybercrime. Attacks that once demanded a working knowledge of identity protocols, cloud account structures, social engineering, and money-laundering logistics can now be packaged into a chatbot interface and rented by the month. That "cybercrime-as-a-service" model mirrors the legitimate SaaS economy: a flat fee buys access to tooling, support, and continuous updates, letting less-skilled operators run sophisticated intrusion and fraud campaigns that would previously have been out of reach.
The abuse of OAuth device-code flows is also a reminder that identity infrastructure — not just software vulnerabilities — is squarely in attackers' sights. Device-code phishing sidesteps passwords and many forms of multi-factor authentication entirely, since victims are led to authenticate on a genuine Microsoft page and simply hand over a valid session token. Organizations that support device-code authentication should review whether it is necessary, restrict it through conditional access policies, and train users to be suspicious of unsolicited device-login prompts.
Looking Ahead
The EvilTokens case underscores an evolving playbook for taking down AI-enabled cybercrime: civil litigation to seize infrastructure at scale, paired with intelligence-sharing that hands domestic law enforcement — in this case, the Metropolitan Police — a direct path to arrests. With roughly 1,000 subscribers reportedly having used the service before its disruption, investigators in multiple countries are likely still working through the fallout, and further arrests tied to the platform's customer base would not be surprising. Microsoft says it has notified affected organizations and is helping them remediate compromised accounts, but the case is likely to be cited for some time as an early template for dismantling AI-powered cybercrime platforms before they scale further.