Monday, 28 September 2026

Where technology leaders come to think out loud

The BriefCybersecurity

Microsoft and the Met dismantle EvilTokens, an AI phishing kit for hire

The Telegram-sold service charged $1,500 (£1,100) to join and $500 (£370) a month, sidestepped multifactor authentication on Microsoft 365 and used a chatbot to read stolen inboxes for payment fraud

The facts
  • EvilTokens launched in February 2026 and was sold on Telegram for a $1,500 (£1,100) joining fee plus $500 (£370) a month.
  • Microsoft links the service to more than 12,000 compromised inboxes across over 10,000 organizations worldwide.
  • Met officers arrested two men, aged 32 and 38, and released them on police bail.
  • Microsoft seized 50 websites and disabled more than 150 domains under a US court order on 22 September.
  • The action is the Digital Crimes Unit’s 40th court-authorized disruption.
What it means for partners

Every MSP that sold MFA as the end of the phishing conversation now has customers who can be compromised for $500 a month by someone who never sees a password. The pitch moves to what sits behind MFA: conditional access, sign-in monitoring and a finance process that confirms payment changes on a second channel, the last of which Microsoft itself recommends. Managed security service providers and identity-led resellers who can show a tenant what its sign-in flows allow are the winners. Distributors should note that wholesale distribution sat first on Microsoft’s list of victim sectors.

“The infrastructure supporting EvilTokens has been disrupted, but the model it demonstrated will not disappear with it.”Steven Masada, associate general counsel and general manager, Digital Crimes Unit, Microsoft

Microsoft’s Digital Crimes Unit (DCU) and the Metropolitan Police have shut down EvilTokens, a phishing-as-a-service platform that Microsoft links to more than 12,000 compromised email inboxes at over 10,000 organizations since it launched in February 2026. On 22 September Microsoft said it had seized 50 websites and disabled more than 150 domains under an order from the US District Court for the Eastern District of Virginia. Met officers had already arrested two men, aged 32 and 38, on suspicion of running the service: The Register dates the arrests to 18 September, Microsoft’s blog to 11 September.

The kit did not steal passwords. It tricked victims into entering an authentication code on Microsoft’s genuine sign-in page, giving the attacker persistent access without tripping multifactor authentication (MFA). A chatbot then read the captured mailbox and mapped who approved payments, who moved money and which threads discussed wire transfers, so a buyer could pick a target for invoice fraud in minutes. Microsoft says the largest victim counts were in the US, Canada, the UK, Australia, India and France, in sectors from wholesale distribution and construction to financial services and healthcare.

Two named defendants and a 40th takedown

The civil complaint, filed on 22 September alongside the healthcare threat-sharing body Health-ISAC, names Felix Utomi, Waidi Segun Adams and five unnamed defendants. Seven organizations, among them Cloudflare, OpenAI and Coinbase, supported the action, which Microsoft counts as the DCU’s 40th court-authorized disruption and its first against a service that used AI from intrusion to fraud. The Register reported on 22 September that the two men, alleged to have administered the EvilTokens website, had been released on bail.

AdvertisementZoomInfo
More from The BriefAll briefs
Bytes Technology Group

Bytes lifts its FY27 outlook as costs hold back operating profit

Arctic Wolf

Arctic Wolf opens a sensorless MDR tier to MSPs only

Vectra AI

Vectra AI launches Ascent partner program with three levels

Capgemini

Capgemini sees $230bn of bank payments revenue at risk from stablecoins

Get the briefs every week in The VETTDD Briefing.