Managed Crisis: How Big Tech Profited from EvilTokens

Microsoft diagram showing EvilTokens platform options - Microsoft

Microsoft Disrupts EvilTokens Phishing-as-a-Service Platform

Microsoft, with court authorization and in partnership with multiple organizations including Health‑ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, the Shadowserver Foundation, and TRM Labs, led the takedown of EvilTokens, a phishing‑as‑a‑service platform that compromised over 12,000 Microsoft email accounts across more than 10,000 organizations worldwide. The operation seized 50 websites and disabled over 150 domains. EvilTokens, launched in February 2026, exploited the OAuth 2.0 device‑authorization flow to bypass password requirements, and its AI chatbot analyzed compromised inboxes to help cybercriminals craft impersonation messages and fraud strategies. Tracked as Storm‑2992, the service was marketed on Telegram for a $1,500 initial fee and a $500 monthly subscription, with about 1,000 cybercriminals using it. Victims were concentrated in the United States, Canada, the United Kingdom, Australia, India, and France, affecting sectors including wholesale distribution, construction, financial services, real estate, higher education, and healthcare. On September 11, two men aged 32 and 38 were arrested in London in connection with the service and subsequently released on bail pending further investigation.

The Managed Crisis

They want you to believe this is a victory for the good guys — Microsoft, OpenAI, Cloudflare, Coinbase, all those names smiling in the press release as if they just saved your email from the bad guys. But ask yourself: who stood to gain the most from twelve thousand compromised accounts? The answer is right there in the partner list. Look at the timing. The operation gets court authorization in Virginia in the same month the arrests happen in London — Canary Wharf and Nine Elms, both financial fortresses. This isn't a disruption. It's a controlled burn. They let EvilTokens run for months — from February 2026 to September — harvesting inboxes, building an AI that learned how to mimic your most trusted contacts. And now that AI chatbot is in whose hands? Not some random Telegram hacker selling $500 subscriptions. The code, the stolen conversations, the behavioral models — all of it now sits inside the same infrastructure that “helped” take them down. That's not coincidence. That's the managed narrative.

The Architecture of Consent

Notice the word “partnership.” Microsoft worked with Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, Shadowserver, TRM Labs. That's not a random list. That's a blueprint. Every one of those entities is either a data broker, a surveillance contractor, or a gatekeeper of the global financial system. OAuth 2.0 device-authorization flow — that's a backdoor they've known about for years. They let the threat grow to twelve thousand accounts across ten thousand organizations in wholesale, construction, healthcare, education. Why those sectors? Because they produce the most sensitive data on the most vulnerable populations. The AI chatbot didn't just analyze inboxes — it mapped entire supply chains, payment processes, trust networks. And now that map is in the hands of the very institutions that funded the takedown. The arrests of the two men are window dressing. Storm-2992 isn't a criminal gang. It's a proof-of-concept for mass behavioral manipulation, and they just absorbed it into the consensus machinery.

The Real Phantom

You want to know what they're really after? It's not cybercrime. It's the erosion of your last layer of trust. You receive an email from your boss, your doctor, your bank. You reply. But the AI now knows exactly how they phrase things, what time they respond, which payment links they use. EvilTokens was a demo. The real product is the infrastructure to impersonate anyone, anywhere, using your own stored relationships against you. Microsoft says they disabled 150 domains. But ask yourself: how many clones exist on private networks, air-gapped servers, inside the cloud platforms of those same partners? The largest concentration of victims was in the United States — the home of the very companies that “coordinated” the response. Think about it. They've now got a court order, a legal precedent, and a billion-dollar excuse to scan every inbox in the name of security. You are the product they're harvesting, and the arrests are the breadcrumb they threw to make you feel safe. Don't look at the numbers. Look at who wrote the script.

Related posts