HomeIntelligenceBrief
BREACH BRIEF 🟠 High ThreatIntel

Microsoft Takes Down AI‑Powered Phishing Service ‘EvilTokens’, Two Suspects Arrested in the UK

Microsoft secured a court order to shut down the AI‑driven phishing platform EvilTokens and, with U.K. police, arrested two alleged operators. The incident underscores the need for continuous third‑party risk monitoring and audit‑ready evidence of threat‑intel actions.

Verisq™ Intelligence · 📅 September 22, 2026 · 📰 therecord.media
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
2 recommended
📰
Source
therecord.media

Microsoft Takes Down AI‑Powered Phishing Service ‘EvilTokens’; Two Suspects Arrested in the UK

What Happened – Microsoft’s Digital Crimes Unit obtained a court order to shut down the “EvilTokens” AI‑chatbot, a subscription‑based service that sold cybercriminals automated phishing playbooks. Working with the U.K. Metropolitan Police, the operation led to the arrest of two alleged operators.

Why It Matters for Trust & Control Assurance

  • The case illustrates the risk of malicious third‑party services that can be weaponized against any organization’s users. Continuous monitoring of external threat‑as‑a‑service providers is a core control‑assurance activity.
  • Evidence of the takedown (court filings, arrest records) provides a defensible audit trail that demonstrates due diligence in vendor oversight and fraud‑prevention programs.

Who Is Affected – Health‑sector groups (partnered with Health‑ISAC), financial services, and any enterprise that relies on email communications for business processes.

Recommended Actions

  • Review your third‑party risk program to include monitoring of AI‑enabled malicious services and phishing‑as‑a‑service platforms.
  • Capture and retain evidence of any investigations, legal actions, or threat‑intel reports related to such services to support audit readiness.

Technical Notes – EvilTokens operated via a Telegram bot, charging a $1,500 onboarding fee plus $500 monthly. It leveraged multiple AI models (including OpenAI) to analyze breached inboxes, map victim relationships, and auto‑generate fraudulent messages. Source: The Record

📰 Original Source
https://therecord.media/two-arrested-in-uk-after-microsoft-takedown-eviltokens

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →