A major AI-powered phishing service has lost access to its key infrastructure
Microsoft, other tech partners disrupted domains linked to EvilTokens.

TL;DR
- Microsoft has taken down the infrastructure of EvilTokens, an AI-powered cybercrime platform.
- EvilTokens used AI chatbots to analyze stolen corporate data and facilitate fraud.
- The platform helped hackers compromise over 12,000 email inboxes in 10,000 organizations.
- Microsoft seized 50 websites and disabled over 150 domains tied to EvilTokens' operations.
- Two individuals were arrested in the UK in connection with the platform.
- EvilTokens operated on a subscription model, charging hackers for access to its tools.
- The AI tools condensed tasks that would normally take hackers days into hours.
- Microsoft observed the highest victim activity in the U.S., Canada, UK, Australia, India, and France.
- Coinbase traced approximately $1.1 million in revenue to the platform.
- Evidence suggests EvilTokens itself was partially built using AI tools.