Microsoft takes down EvilTokens phishing service that used AI to mine hacked inboxes for payment fraud
Microsoft disrupted EvilTokens, a phishing service that used AI to compromise 12,000 accounts at 10,000 organizations, stealing payment data. The service charged fees and automated fraud schemes. Microsoft seized 50 websites and 150 domains, with UK police arresting two suspects. Affected sectors included financial services and healthcare, primarily in the US and Canada.
How this was made

The 30-second read
Why it matters
The disruption reduces immediate fraud risk but underscores the need for stronger identity protection across the industry.
Market read
First report of a major AI‑enabled phishing takedown involving Microsoft, relevant for security‑focused investors.
What to watch
Potential increase in demand for Microsoft's security products and services as enterprises seek stronger protection.
Background
Cybercriminals used AI‑driven phishing to harvest payment data from Microsoft accounts; law enforcement intervened.
Ticker impact
Microsoft disclosed it disrupted the EvilTokens phishing service that compromised 12,000 accounts, a new enforcement action.
Neutral to slightly positive impact as investors view the action as a risk mitigation.
While the news is material and novel, it does not directly affect revenue; market reaction is likely modest.
Market effects
Highlights growing cybersecurity threats for cloud and identity services, prompting heightened focus on security solutions.
Primarily affects North American and European markets where Microsoft has large enterprise base.
Sets a precedent for coordinated takedowns of AI‑assisted phishing services worldwide.
Counterpoint
The enforcement may be seen as a minor operational issue with limited financial impact on Microsoft.
Key entities
- CompanyMicrosoft
Provider of cloud and identity services, subject of the enforcement action.
- Illicit ServiceEvilTokens
AI‑assisted phishing platform taken down by Microsoft and authorities.


