VYPR
breachPublished Sep 22, 2026· 4 sources

Microsoft and Partners Dismantle EvilTokens, AI-Powered Financial Fraud Service

Microsoft, alongside industry partners, has disrupted EvilTokens, a sophisticated cybercrime-as-a-service platform that utilized AI to facilitate financial fraud, impacting over 10,000 organizations globally.

A significant cybercrime operation has been dismantled following a coordinated effort by Microsoft and its industry partners. The operation targeted EvilTokens, a cybercrime-as-a-service platform that leveraged artificial intelligence to automate and enhance financial fraud schemes. The takedown, executed under a federal court order on September 15, 2026, resulted in the seizure of 50 websites used by the platform and the disabling of over 175 associated domains.

Launched in February 2026, EvilTokens quickly became a formidable tool for cybercriminals, reportedly used by approximately 1,000 individuals. Microsoft described the platform as "a powerful cybercrime platform that used AI at every step of the attack chain—from compromising email accounts to designing intricate roadmaps for financial fraud and scams." The core of EvilTokens was an AI-powered chatbot that enabled attackers to analyze victim inboxes, identify trusted relationships, and pinpoint opportunities for financial exploitation, moving beyond simple phishing to sophisticated impersonation and fraud.

The service specialized in business email compromise (BEC) attacks by stealing session tokens. This allowed cybercriminals to gain persistent access to victim inboxes, bypassing security measures like multi-factor authentication and email gateways. With this access, attackers could monitor communications, identify payment authorizations, and craft highly convincing fraudulent requests, often impersonating executives or trusted vendors.

While the full extent of fraud facilitated by EvilTokens is difficult to quantify, Microsoft was able to correlate at least 13 complaints filed with the FBI's Internet Crime Complaint Center (IC3) to the platform's activities, resulting in approximately $1.7 million in reported losses. The company acknowledges this figure is a conservative estimate, as many incidents go unreported and not all victims can be definitively linked to specific campaigns.

Victims of EvilTokens were primarily located in the United States, Canada, the United Kingdom, Australia, India, and France, though compromised email domains spanned 79 countries. Microsoft identified two key individuals behind the platform, Felix Utomi and Waidi Segun Adams, attributing its development and support to a threat actor group known as Storm-2992. Acting on intelligence provided by Microsoft, the UK's Metropolitan Police arrested Utomi and Adams in the greater London area on September 18, seizing their digital devices as part of an ongoing investigation.

Further investigation, supported by companies like Coinbase, revealed that EvilTokens generated significant revenue, with Coinbase tracing about $1.1 million in payments from its customers. The service was marketed on Telegram, requiring a $1,500 initiation fee and a $500 monthly subscription, making sophisticated cybercrime tools accessible to a wider audience. The platform integrated specialized tools for identity attacks, cloud systems, social engineering, and financial fraud, significantly lowering the barrier to entry for aspiring cybercriminals.

Microsoft and its partners, including Health-ISAC, Cloudflare, OpenAI, Shadowserver, and TRM Labs, have notified potential victims, shared indicators of compromise, and provided intelligence to law enforcement. While the EvilTokens infrastructure has been disrupted, Microsoft warns that the underlying model of commercially run cybercrime services, enhanced by AI, will likely persist, underscoring the need for continued vigilance and advanced security measures.

The operation, which saw the arrest of two alleged administrators in the UK, marks Microsoft's first action against an end-to-end AI-enabled cybercrime service. The EvilTokens kit's AI chatbot was capable of analyzing victim inboxes to identify targets, suggest impersonations, and optimize fraud strategies, significantly increasing its effectiveness and reach.

The disruption of EvilTokens by Microsoft and law enforcement has led to the arrest of two individuals in the UK, aged 32 and 38, who are suspected operators of the AI-powered cybercrime service. These arrests followed a report by Microsoft to the Metropolitan Police Service in August, with warrants executed on two locations. The arrested men have been released on bail pending further investigation, while Microsoft indicated that other individuals may have also supported the platform.

This Microsoft Security Blog post provides a deeper technical dive into the EvilTokens phishing-as-a-service (PhaaS) platform, detailing its abuse of the device code authentication flow to steal tokens and enable sophisticated BEC campaigns. It attributes the platform's development and support to the threat actor tracked as Storm-2992 and outlines how AI is used for post-compromise reconnaissance and to bypass security controls, impacting over 10,000 organizations globally.

Synthesized by Vypr AI