What EvilTokens sold
Microsoft’s Digital Crimes Unit said on 22 September that it had disrupted EvilTokens, a subscription cybercrime service that launched in February 2026 and was sold over Telegram for a $1,500 joining fee and $500 a month.
The product was device-code phishing: tricking a target into approving a sign-in on the attacker’s device, which hands over session tokens rather than a password. Microsoft notes that this access “could persist even after a password reset if the associated sessions and tokens were not also revoked.”
What made it different was what happened next. EvilTokens bundled a chatbot that read the compromised mailbox and worked out who mattered in the organisation — reporting lines, trusted relationships, who authorises payments, who would not question an invoice. It then recommended a fraud strategy and drafted the messages, impersonating a contact the recipient already trusted.

The scale, and the takedown
Microsoft puts the damage at more than 12,000 compromised inboxes across over 10,000 organisations worldwide, concentrated in the United States, Canada, the United Kingdom, Australia, India and France. The affected sectors were ordinary ones: wholesale distribution, construction, financial services, higher education and healthcare.
The disruption was authorised by the US District Court for the Eastern District of Virginia. Microsoft and Health-ISAC, working with Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation and TRM Labs, seized 50 websites and disabled more than 150 further domains. The Metropolitan Police’s cybercrime unit arrested two men, aged 32 and 38, on 11 September. Both were released on police bail while the investigation continues.
Microsoft says this was the Digital Crimes Unit’s fortieth court-authorised disruption, and its first against an end-to-end AI-enabled cybercrime service.

What actually changed
The technique here is old. Device-code phishing predates this service, and business email compromise has been the most expensive category of cybercrime for years. What the chatbot removed was the labour.
Reading a stolen mailbox well enough to write a convincing invoice fraud used to take a person hours or days of patient work, and it was the step that limited how many victims one operator could handle. A subscriber with this tool got that reconnaissance in the time it takes to answer a prompt.
Microsoft’s own advice reflects the shift: organisations should now assume that once an inbox is compromised, criminals may understand its contents in minutes rather than days. That is a meaningful change to incident response. A detection window measured in days was survivable because the attacker also needed days. It is not survivable against an attacker who needs minutes, and revoking sessions and tokens — not just resetting the password — becomes the difference between containing an intrusion and merely appearing to.