Microsoft announced the court-authorized takedown of the EvilTokens device-code phishing service on September 22, 2026, seizing 50 phishing kit websites and coordinating with UK police, who arrested two suspects connected to the operation.
The U.S. District Court for the Eastern District of Virginia authorized the takedown. EvilTokens is linked to 12,000 inbox compromises across 10,000 organizations globally. The service integrated AI “at every step of the attack chain,” according to Microsoft’s disclosure.
Court-Authorized Seizure of 50 EvilTokens Phishing Kit Websites
Microsoft obtained authorization from the U.S. District Court for the Eastern District of Virginia to seize 50 websites operated by the EvilTokens phishing-as-a-service platform. The court order allowed Microsoft to take control of the domain infrastructure EvilTokens used to host phishing kits and credential harvesting pages.
EvilTokens operated as a phishing-as-a-service platform, providing paying subscribers with pre-built device-code phishing tools, credential harvesting infrastructure, and automated attack workflows. This business model lowered the technical barrier for attackers seeking to compromise email accounts at scale.
Device-Code Phishing Exploits OAuth Authentication Flow
Device-code phishing targets the OAuth device authorization flow, a mechanism that allows users to authenticate on devices with limited input capabilities by entering a code on a separate trusted device. EvilTokens’ phishing kits tricked users into authorizing malicious applications by presenting fake login prompts and device-code entry screens.
Once a victim entered their credentials and authorized the device code, the attacker gained access to the victim’s email account and cloud services. The compromised accounts were then available for further exploitation—business email compromise, lateral movement within the victim’s organization, or sale to other threat actors.
AI Integration Across Attack Chain Automation
Microsoft’s disclosure states that EvilTokens used AI “at every step of the attack chain.” The platform automated phishing email generation, credential harvesting page customization, and victim response handling through AI-driven workflows.
This level of automation allowed EvilTokens subscribers to launch phishing campaigns with minimal manual effort. The service generated convincing phishing content, adapted pages to match target organizations’ branding, and processed stolen credentials automatically, delivering compromised account access to subscribers in a turnkey manner.
12,000 Inbox Compromises Across 10,000 Organizations Globally
EvilTokens is linked to 12,000 inbox compromises spanning 10,000 organizations worldwide. The global reach reflects the phishing-as-a-service model’s scalability—subscribers could target organizations across industries and geographies without maintaining their own infrastructure.
The 12,000-to-10,000 ratio suggests some organizations suffered multiple account compromises, indicating either targeted campaigns against specific entities or opportunistic compromise of multiple users within the same organization following initial access.
UK Police Arrest Two Suspects in Connection with EvilTokens
UK law enforcement arrested two suspects on September 22, 2026, in connection with the EvilTokens operation. Microsoft’s disclosure did not identify the suspects, describe their roles in the platform, or specify whether they operated the infrastructure, developed the phishing tools, or served as administrators.
The arrests signal law enforcement action beyond infrastructure seizure. Disrupting the individuals behind phishing-as-a-service platforms can degrade the ecosystem more effectively than domain takedowns alone, which threat actors can recover from by registering new domains.
Multi-Organization Collaboration in Disruption Effort
Microsoft coordinated the takedown with Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, and The Shadowserver Foundation. Each organization contributed capabilities or intelligence to the disruption operation.
Cloudflare likely assisted with domain seizure and DNS-level blocking. Coinbase’s involvement suggests cryptocurrency payment flows connected to EvilTokens subscriptions or monetization. OpenAI’s participation may relate to AI model abuse, given EvilTokens’ use of AI throughout its attack chain. Railway, SpyCloud, and The Shadowserver Foundation contributed threat intelligence, compromised credential data, or infrastructure mapping.
Health-ISAC’s participation highlights EvilTokens’ impact on healthcare organizations. Phishing-as-a-service platforms often target healthcare entities due to their high-value patient data, interconnected supply chains, and operational sensitivity to email compromise incidents.
The collaborative model reflects the reality that phishing-as-a-service disruption requires coordination across cybersecurity vendors, cloud providers, payment processors, and sector-specific information sharing organizations. No single entity holds all the technical levers or legal authority needed to dismantle a global phishing operation.
Organizations that experienced email compromise incidents in recent months should review account activity logs for unauthorized access, review forwarding rules and inbox permissions for attacker-configured persistence mechanisms, and reset credentials for accounts accessed during the compromise window.
