THE CRUNCH

Microsoft has disrupted EvilTokens, an AI-powered phishing platform used by cybercriminals to target organisations globally. The service, active since February 2026, compromised more than 12,000 email accounts at over 10,000 organisations. Microsoft seized 50 websites and disabled more than 150 domains linked to the platform. Two men, Felix Utomi and Waidi Segun Adams, have been arrested in the UK in connection with,

the operation. EvilTokens used AI to customise phishing emails and to decide which targets to attack and how to exploit them. The platform exploited device code phishing, a method where attackers trick users into entering a code on a separate device to gain access without passwords. Microsoft believes the platform itself was also coded using AI. The takedown involved contributions from several security firms, including SpyCloud, Cloudflare and OpenAI.

Why It Matters: The disruption of EvilTokens highlights how AI is increasingly being used to automate and scale cybercrime. The platform’s use of AI to customise attacks and select targets demonstrates a shift towards more sophisticated and efficient phishing operations. The involvement of major tech companies in the takedown underscores the collaborative effort required to combat such threats.

WHAT HAPPENS NEXT

Microsoft has seized the platform's websites and disabled its domains. The two arrested men are suspected of operating the service.