Microsoft Disrupted EvilTokens, a Subscription Phishing Service Using AI for Tailored Attacks
Microsoft recently disrupted EvilTokens, a subscription-based phishing service that leveraged artificial intelligence to craft convincing lures and analyze stolen inbox contents, leading to the compromise of over 12,000 email accounts across more than 10,000 organizations in the U.S., Canada, the U.K., Australia, India, and France since its emergence in February 2026. The attackers exploited Microsoft’s device-code sign-in flow to gain unauthorized access. Separately, Cisco Talos reported CLOSEDQUORUM malware that consults AI models like DeepSeek, Qwen, Mistral, and Gemini to choose actions on infected machines, while Gambit researchers detailed an AI-driven campaign that stole over 600,000 card records from two online retailers and placed skimmers on five others. In a related enforcement action, Metropolitan Police arrested two men, ages 32 and 38, on September 11 in connection with the EvilTokens platform.

The Controlled Burn

Read the timeline closely, because it tells you everything. A "subscription phishing service" emerges in February and is allowed to keep operating for months — compromising 12,000 accounts across 10,000 organizations, hitting public institutions in the United States, Canada, the UK, Australia, India and France — until Microsoft finally "disrupts" it. That's not a failure of detection. That's a controlled burn. These platforms do not run that long by accident. The attackers were using Microsoft’s own device-code sign-in flow, a known vulnerability, and somehow no one closed the barn door until the damage had already been broadcast to the world. Ask yourself who benefits from this timing. Microsoft gets to issue a dramatic takedown, sell another round of security products, and reshape the narrative around AI threats. Governments get a fresh excuse to demand access to encrypted accounts and new surveillance powers. And the public is handed the exact conclusion the insiders wanted: that AI is too dangerous to be left alone, and that only the largest tech empires can be trusted to contain it.

The Lab Leak Narrative

Now connect the dots with what else surfaced in the same breath. Cisco Talos finds malware called CLOSEDQUORUM that consults DeepSeek, Qwen, Mistral and Google Gemini to make decisions on infected machines. Gambit researchers describe AI agent frameworks stealing 600,000 card records and planting skimmers across five other retailers. Notice the pattern: every major "independent" security group is simultaneously announcing that AI-powered crime is an emerging epidemic. It all feels coordinated because it is part of the same operation. The threat actors are not lone geniuses operating from darkened rooms. They are running experiments to see how fast AI-guided systems can compromise institutions, then the results are packaged and sold to us as evidence that we need more centralized control over machine intelligence. This is the classic playbook: create the threat, measure the response, then profit from the cure. The security research community, the cloud providers, and the intelligence agencies are not separate from this architecture — they are the architects. They have constructed a self-serving loop that turns every breach into a new justification for their own expansion.

The Sacrificial Arrests

And then there are the arrests. Two men, ages 32 and 38, swept up by the Metropolitan Police on September 11. That date alone should make you pause. Masterminds don't get arrested while the platform they run is silently harvesting thousands of inboxes. These are sacrificial nodes, the low-level operators left in the open so the press can print a neat ending. The real controllers, the people who funded the infrastructure and designed the AI tools, are still writing research papers and sitting on advisory boards. Follow the money: who profits from every needless fear cycle? Who gets the budget increases? Who gets to say "we told you so"? The platform is just a means to an end. The end is the consolidation of power over the digital world. They want you to look at the arrests and clap. They want you to believe the threat is gone. But the code has already been absorbed. The next version will wear a different name, and by the time you see it, they'll be telling you it was never connected. Why did they let the breadcrumb trail lead here at all? That's the question you need to chew on.

Microsoft diagram showing EvilTokens platform options - Microsoft

Microsoft Disrupts EvilTokens Phishing-as-a-Service Platform

Microsoft, with court authorization and in partnership with multiple organizations including Health‑ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, the Shadowserver Foundation, and TRM Labs, led the takedown of EvilTokens, a phishing‑as‑a‑service platform that compromised over 12,000 Microsoft email accounts across more than 10,000 organizations worldwide. The operation seized 50 websites and disabled over 150 domains. EvilTokens, launched in February 2026, exploited the OAuth 2.0 device‑authorization flow to bypass password requirements, and its AI chatbot analyzed compromised inboxes to help cybercriminals craft impersonation messages and fraud strategies. Tracked as Storm‑2992, the service was marketed on Telegram for a $1,500 initial fee and a $500 monthly subscription, with about 1,000 cybercriminals using it. Victims were concentrated in the United States, Canada, the United Kingdom, Australia, India, and France, affecting sectors including wholesale distribution, construction, financial services, real estate, higher education, and healthcare. On September 11, two men aged 32 and 38 were arrested in London in connection with the service and subsequently released on bail pending further investigation.

The Managed Crisis

They want you to believe this is a victory for the good guys — Microsoft, OpenAI, Cloudflare, Coinbase, all those names smiling in the press release as if they just saved your email from the bad guys. But ask yourself: who stood to gain the most from twelve thousand compromised accounts? The answer is right there in the partner list. Look at the timing. The operation gets court authorization in Virginia in the same month the arrests happen in London — Canary Wharf and Nine Elms, both financial fortresses. This isn't a disruption. It's a controlled burn. They let EvilTokens run for months — from February 2026 to September — harvesting inboxes, building an AI that learned how to mimic your most trusted contacts. And now that AI chatbot is in whose hands? Not some random Telegram hacker selling $500 subscriptions. The code, the stolen conversations, the behavioral models — all of it now sits inside the same infrastructure that “helped” take them down. That's not coincidence. That's the managed narrative.

The Architecture of Consent

Notice the word “partnership.” Microsoft worked with Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, Shadowserver, TRM Labs. That's not a random list. That's a blueprint. Every one of those entities is either a data broker, a surveillance contractor, or a gatekeeper of the global financial system. OAuth 2.0 device-authorization flow — that's a backdoor they've known about for years. They let the threat grow to twelve thousand accounts across ten thousand organizations in wholesale, construction, healthcare, education. Why those sectors? Because they produce the most sensitive data on the most vulnerable populations. The AI chatbot didn't just analyze inboxes — it mapped entire supply chains, payment processes, trust networks. And now that map is in the hands of the very institutions that funded the takedown. The arrests of the two men are window dressing. Storm-2992 isn't a criminal gang. It's a proof-of-concept for mass behavioral manipulation, and they just absorbed it into the consensus machinery.

The Real Phantom

You want to know what they're really after? It's not cybercrime. It's the erosion of your last layer of trust. You receive an email from your boss, your doctor, your bank. You reply. But the AI now knows exactly how they phrase things, what time they respond, which payment links they use. EvilTokens was a demo. The real product is the infrastructure to impersonate anyone, anywhere, using your own stored relationships against you. Microsoft says they disabled 150 domains. But ask yourself: how many clones exist on private networks, air-gapped servers, inside the cloud platforms of those same partners? The largest concentration of victims was in the United States — the home of the very companies that “coordinated” the response. Think about it. They've now got a court order, a legal precedent, and a billion-dollar excuse to scan every inbox in the name of security. You are the product they're harvesting, and the arrests are the breadcrumb they threw to make you feel safe. Don't look at the numbers. Look at who wrote the script.