Skip to content
See the World Through ScienceA project of ALLATRA

Microsoft and UK Police Take Down a Phishing Service Rented to Criminals by the Month

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

The revolving New Scotland Yard sign standing outside a glass-fronted office tower in London.
The New Scotland Yard sign outside the headquarters of London's Metropolitan Police Service, the force that made the two arrests (illustrative)."New Scotland Yard" by Can Pac Swire, via flickr, BY-NC · BY-NC

Microsoft said on Sept. 22 that its Digital Crimes Unit, working with partners, has disrupted the infrastructure behind EvilTokens, a phishing service sold to criminals on a monthly subscription through Telegram. The platform emerged in February 2026 and was linked to more than 12,000 compromised email inboxes across more than 10,000 organizations worldwide.

Its published analysis says the service handed subscribers AI tools for tailoring phishing emails and for sorting through stolen inboxes to find high-value targets, and recommends that organizations block device code sign-in wherever possible and scope any exception narrowly to the devices that need it. That sign-in method exists for equipment that cannot show a normal login page, such as printers, televisions and conferencing hardware.

Steven Masada, associate general counsel at the Digital Crimes Unit, told Recorded Future News that the action rested on a lawsuit filed with the health-sector nonprofit Health-ISAC in U.S. District Court, and that Microsoft worked with dozens of companies to seize 50 websites used to run the service and disable 150 further domains.

A Metropolitan Police Service spokesperson confirmed to the same outlet that two men were arrested on suspicion of making articles for use in fraud and money laundering. Officers carried out warrants on Sept. 18, and both men have been released on bail while the investigation continues.

Detective Inspector Serena D'Adamo, whose team led the investigation, said: "Phishing services bring misery to thousands, taking money from everyday people across the world."

Microsoft said the organizations it saw attacked were concentrated in the United States, Canada, the United Kingdom, Australia, India and France, across industries including construction, financial services, higher education and healthcare.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

Microsoft and UK Police Take Down a Phishing Service Rented to Criminals by the Month

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.