Microsoft, Coinbase, and law enforcement agencies have dismantled EvilTokens, a subscription-based phishing-as-a-service platform that operated globally. The operation resulted in the arrest of two individuals in London on September 11, 2026, and the seizure of 50 websites and disabling of more than 150 domains associated with the service.
Scale of the Operation
EvilTokens compromised over 12,000 email inboxes across more than 10,000 organizations spanning 79 countries. The attacks were concentrated in the United States, Canada, the United Kingdom, Australia, India, and France. Approximately 1,000 cybercriminals used the service, which launched in February 2026.
How EvilTokens Operated
The platform charged a $1,500 setup fee and $500 monthly subscription. Its primary attack method was device-code attacks, a technique that tricks users into authenticating on a legitimate Microsoft login page while secretly transferring their session tokens to attackers, effectively bypassing multi-factor authentication.
EvilTokens included an AI chatbot designed to analyze compromised inboxes for financial information, identify high-value targets within organizations, and plan follow-up attacks. The service was marketed through Telegram channels.
Financial Tracing and Takedown
Coinbase's blockchain analysis team traced approximately $1.1 million in illicit revenue across four Tron addresses and more than 700 distinct deposit addresses linked to the operation. The takedown proceeded under a US District Court order authorizing the seizure and domain disablement.
Two individuals aged 32 and 38 were arrested by the UK Metropolitan Police on September 11, 2026, and subsequently released on bail.
Context
The operation represents another instance of public-private coordination against cybercrime. In March 2026, a similar collaboration took down Tycoon 2FA, a phishing service using comparable multi-factor authentication bypass techniques on Microsoft accounts.


