Two men have been arrested in London as part of a Microsoft-led takedown of an AI-powered phishing service linked to more than 12,000 compromised email inboxes across 10,000 organisations worldwide.
The Metropolitan Police arrested the two men, aged 32 and 38, who are alleged to have acted as administrators of the “EvilTokens” phishing-as-a-service platform. Digital devices were seized, and both men were released on bail while the investigation continues.
Microsoft’s Digital Crimes Unit (DCU) seized 50 websites used to operate the service and disabled more than 150 additional domains tied to its supporting infrastructure, under authorisation from the US District Court for the Eastern District of Virginia.
EvilTokens was sold through Telegram for a $1,500 initiation fee plus a $500 recurring subscription, and is described by Microsoft as the first end-to-end AI-enabled cybercrime service it has acted against. The operation marks the DCU’s 40th court-authorised disruption over nearly two decades.
The highest concentrations of victims were in the United States, Canada, the United Kingdom, Australia, India and France.
Health-ISAC joined as a co-plaintiff in the action, with partners including Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation and TRM Labs.
Detective Inspector Serena D’Adamo of the Metropolitan Police said: “Phishing services bring misery to thousands, taking money from everyday people across the world. The Met remains committed to holding people to account who facilitate criminal enabling functions and think they can remain undetected.”
Steven Masada, associate general counsel and general manager of Microsoft’s Digital Crimes Unit, said: “The infrastructure supporting EvilTokens has been disrupted, but the model it demonstrated will not disappear with it. For organizations, the lesson is: assume that once an inbox is compromised, criminals may understand its contents in minutes, not days. Strong identity protections and monitoring remain essential, but organizations should also independently verify requests to change payment information, redirect funds or approve unusual transactions through a trusted second channel.”
Reporting based on: Microsoft: “Disrupting EvilTokens: The AI Chatbot Built for Cybercrime”, 22 September 2026, via The Register, 22 September 2026.

