Microsoft and UK Police Take Down a Phishing Service Rented to Criminals by the Month

Microsoft said on Sept. 22 that its Digital Crimes Unit, working with partners, has disrupted the infrastructure behind EvilTokens, a phishing service sold to criminals on a monthly subscription through Telegram. The platform emerged in February 2026 and was linked to more than 12,000 compromised email inboxes across more than 10,000 organizations worldwide.
Its published analysis says the service handed subscribers AI tools for tailoring phishing emails and for sorting through stolen inboxes to find high-value targets, and recommends that organizations block device code sign-in wherever possible and scope any exception narrowly to the devices that need it. That sign-in method exists for equipment that cannot show a normal login page, such as printers, televisions and conferencing hardware.
Steven Masada, associate general counsel at the Digital Crimes Unit, told Recorded Future News that the action rested on a lawsuit filed with the health-sector nonprofit Health-ISAC in U.S. District Court, and that Microsoft worked with dozens of companies to seize 50 websites used to run the service and disable 150 further domains.
A Metropolitan Police Service spokesperson confirmed to the same outlet that two men were arrested on suspicion of making articles for use in fraud and money laundering. Officers carried out warrants on Sept. 18, and both men have been released on bail while the investigation continues.
Detective Inspector Serena D'Adamo, whose team led the investigation, said: "Phishing services bring misery to thousands, taking money from everyday people across the world."
Microsoft said the organizations it saw attacked were concentrated in the United States, Canada, the United Kingdom, Australia, India and France, across industries including construction, financial services, higher education and healthcare.
