The activities of phishing attack service (PhaaS) EvilTokens were stopped in a joint operation involving several technology companies and UK law enforcement agencies. Two suspects were arrested, 50 websites were disabled and 150 domains were blocked.
Image source: microsoft.com
Participating in this operation are Microsoft Corporation, Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, Shadowserver Foundation and TRM Labs, as well as the Metropolitan Police Cyber Crime Unit. Law enforcement arrested two men, aged 32 and 38, on suspicion of using EvilTokens-related crimes. They are now free on conditional bail pending the investigation; relevant digital assets and other property have been seized as part of the investigation. It is unclear whether the measures taken will help eliminate EvilTokens completely or if the platform will continue to operate. Typically, criminal infrastructure is less resistant to disruption if an organizer is arrested than if law enforcement simply shuts down the equipment.
The EvilTokens project caught the attention of cybersecurity experts in February 2026 and quickly became one of the most popular PhaaS solutions. It’s available on the private market for $1,500, plus a $500 recurring subscription fee. This tool is used to conduct large-scale phishing attacks, publishing fake websites, landing pages, and other resources to steal credentials; the service allows you to intercept session tokens, one-time passwords, and other security codes, allowing attackers to access the victim’s mailbox. The beauty of EvilTokens is its built-in artificial intelligence assistant, which can analyze the contents of victims’ mailboxes, identify the most valuable targets, and even suggest the best way to interact with them. Attackers can use Microsoft Graph for reconnaissance, establishing organizational structure and access rights – which helps them maintain a presence in the system and move within the target network.
EvilTokens operates like a well-run startup, with multiple artificial intelligence models, subscription services, a help desk, management dashboard, and tools to help victims avoid financial fraud when accessing their accounts. According to Microsoft, the corporate email breach resulted in the compromise of more than 12,000 mailboxes at more than 10,000 organizations around the world: the United States, Canada, the United Kingdom, Australia, India and France. These include companies in wholesale trade, construction and financial services, and have impacted the real estate, higher education and health care industries. Microsoft notified victims, assisted in restoring the security of infected mailboxes, and provided information to law enforcement.
If you find an error, select it with your mouse and press CTRL+ENTER.










