Microsoft takes down ‘EvilTokens’ cyber crime service
Microsoft disrupted EvilTokens, an AI-powered phishing service that targeted thousands of orgs in six months. Here's what it reveals about AI crime scaling.

Why it matters
AI is lowering the barrier to entry for large-scale cyber attacks. This takedown shows how threat actors are operationalizing AI for social engineering at scale — a workplace security and policy concern for any organization running cloud infrastructure or handling credentials.
The key facts
10 to knowEvilTokens used AI to target selection, impersonation, and exploitation strategy
Hit thousands of organizations in six months
Phishing-as-a-service model (democratized attack platform)
Microsoft takedown action (law enforcement/platform response)
Credential/token theft as the attack vector (cloud/identity security angle)
EvilTokens operated for ~6 months before takedown
Platform hit thousands of organizations globally
Used AI to automate targeting, impersonation, and exploitation decisions
Phishing-as-a-service model (platform democratizing attacks)
Microsoft enforcement action (law enforcement/security vendor response)
Go to the source
ITProitpro.com
Publisher excerpt: In just six months, the EvilTokens phishing as a service platform hit thousands of organizations worldwide