Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

Microsoft, Coinbase, and Law Enforcement Dismantle EvilTokens Phishing Network

A coordinated operation has shut down EvilTokens, an AI-powered phishing-as-a-service platform that compromised over 12,000 email inboxes across more than 10,000 organizations in 79 countries. Two operators were arrested in London on September 11, 2026.
1 hour ago 7 views
Microsoft, Coinbase, and Law Enforcement Dismantle EvilTokens Phishing Network

Microsoft, Coinbase, and law enforcement agencies have dismantled EvilTokens, a subscription-based phishing-as-a-service platform that operated globally. The operation resulted in the arrest of two individuals in London on September 11, 2026, and the seizure of 50 websites and disabling of more than 150 domains associated with the service.

Scale of the Operation

EvilTokens compromised over 12,000 email inboxes across more than 10,000 organizations spanning 79 countries. The attacks were concentrated in the United States, Canada, the United Kingdom, Australia, India, and France. Approximately 1,000 cybercriminals used the service, which launched in February 2026.

How EvilTokens Operated

The platform charged a $1,500 setup fee and $500 monthly subscription. Its primary attack method was device-code attacks, a technique that tricks users into authenticating on a legitimate Microsoft login page while secretly transferring their session tokens to attackers, effectively bypassing multi-factor authentication.

EvilTokens included an AI chatbot designed to analyze compromised inboxes for financial information, identify high-value targets within organizations, and plan follow-up attacks. The service was marketed through Telegram channels.

Financial Tracing and Takedown

Coinbase's blockchain analysis team traced approximately $1.1 million in illicit revenue across four Tron addresses and more than 700 distinct deposit addresses linked to the operation. The takedown proceeded under a US District Court order authorizing the seizure and domain disablement.

Two individuals aged 32 and 38 were arrested by the UK Metropolitan Police on September 11, 2026, and subsequently released on bail.

Context

The operation represents another instance of public-private coordination against cybercrime. In March 2026, a similar collaboration took down Tycoon 2FA, a phishing service using comparable multi-factor authentication bypass techniques on Microsoft accounts.

Market snapshot

Top cryptocurrency prices

Explore all prices
Market prices will appear after the next scheduled refresh.