Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-23 · updated: 2026-09-23 · tags: [incident, global, phishing] · confidence: high · severity: low · affected_sectors: [global] · au_impact: true

Microsoft's Digital Crimes Unit used a court-authorised action in US District Court, brought with the health-sector non-profit Health-ISAC, to dismantle EvilTokens — an AI-powered phishing and fraud platform sold on Telegram for a US$1,500 initiation fee and a US$500 monthly subscription — seizing 50 websites and disabling 150 further domains. Two men, aged 32 and 38, were arrested by the Metropolitan Police Service's cybercrime team and released on bail. Microsoft says the service launched in February 2026 and was linked to more than 12,000 compromised email inboxes across over 10,000 organisations, concentrated in the United States, Canada, the United Kingdom, Australia, India and France. Its distinctive capability was automating the criminal's decision-making rather than just the lure: the platform summarised and translated mailbox content, mapped organisational roles and trusted relationships, found wire-transfer discussions and vendor invoices, named the "money movers" worth impersonating, and drafted messages in a trusted contact's voice. It abused device-code phishing, in which the victim enters an attacker-supplied code and authorises a session without ever handing over a password — access that can survive a password change. Microsoft describes the takedown as its 40th court-authorised disruption and its first against an end-to-end AI-enabled cybercrime service.

Attribute Detail
Sector Global (Macro)
Date 2026-09-23
Source The Record
Reliability Tier 2