September 27, 2026, 2:04 pm | Read time: 3 minutes
a {<br> text-decoration: none;<br> color: #464feb;<br>}tr th, tr td {<br> border: 1px solid #e6e6e6;<br>}tr th {<br> background-coMicrosoft has taken action against an international fraud network that allegedly operated an AI-powered platform for phishing attacks. According to Microsoft, the service, named EvilTokens, has been used since February 2026 to compromise email accounts worldwide. More than 12,000 mailboxes across over 10,000 organizations were affected, according to the company. Two suspected operators were arrested in the United Kingdom.
Microsoft Takes Action Against Fraud Platform
As Microsoft announced, the Digital Crimes Unit seized 50 websites belonging to the EvilTokens infrastructure with a court order. Additionally, more than 150 other domains were deactivated. This was intended to largely dismantle the technical foundation of the service.
EvilTokens was offered as a so-called Phishing-as-a-Service (PaaS) via Telegram. Criminals could gain access to the platform for a fee. Initially, a fee of $1,500 was required. Subsequently, the operators charged an additional $500 monthly.
How Attackers Gained Access to Accounts
According to Microsoft, the platform exploited a vulnerability in the “Device Code Authentication.” This method is actually intended for devices where input is only possible to a limited extent.
The victims received phishing messages with a link to a manipulated website. There, a code was generated that they were supposed to enter on a legitimate Microsoft login page. This allowed the attackers to access the accounts. According to Microsoft, the method worked even when two-factor authentication was enabled.
Phishing attacks are constantly evolving. Current data shows that criminals in Germany increasingly rely on well-known domestic brands. According to the available data, the Techniker Krankenkasse is now more frequently misused for phishing attacks than Amazon or Microsoft.
Germany Suffers More Hacker Attacks Than Any Other EU Country
Amazon: “Product Counterfeiters Often Also Involved in Human Trafficking”
AI Automatically Analyzed Mailboxes
EvilTokens differed from many other phishing offerings primarily through the use of artificial intelligence. An AI chatbot automatically searched compromised mailboxes for relevant information.
The system searched, among other things, for employees with payment authorizations, ongoing business transactions, and sensitive data. The AI then used the collected information to create fraudulent messages and send them to colleagues or business partners of the affected individuals.
Steven Masada from Microsoft’s Digital Crimes Unit stated that companies must assume that criminals could understand the content of a compromised mailbox within minutes. According to Microsoft, the platform used AI to complete tasks within a few hours that previously took criminals several days.
Investigators Track Millions in Financial Flows
The crypto company Coinbase also participated in the investigations. Payment flows of around $1.1 million between October 2025 and June 2026 were tracked. This corresponds to approximately 963,151 euros.
Also of interest: Microsoft distributes emergency update for Windows 10 and 11
The affected organizations were primarily in the U.S., Canada, UK, Australia, India, and France. The compromised sectors included construction companies, financial service providers, real estate firms, universities, and healthcare facilities. In addition to Microsoft, Cloudflare, Coinbase, OpenAI, SpyCloud, and other partners supported the measures against the network.
Microsoft advises companies to activate Device Code Authentication only where it is truly needed. Additionally, payment instructions should always be verified through a second independent communication channel. Fraud attempts continue to evolve steadily. These include not only phishing emails but also WhatsApp scams or deepfake calls.