Cryptelio

Microsoft and Coinbase Collaborate to Dismantle EvilTokens Cybercrime Network

Cryptelio Editorial Published 23 Sep 2026 · 10:30 UTC
Microsoft and Coinbase Collaborate to Dismantle EvilTokens Cybercrime Network

A collaborative effort involving Microsoft, Coinbase, and law enforcement has led to the takedown of EvilTokens, an AI-powered phishing-as-a-service platform responsible for compromising more than 12,000 email inboxes across over 10,000 organizations in 79 countries. The operation culminated in the arrest of two alleged operators in London on September 11, 2026.

Details of the EvilTokens Operation

EvilTokens, which launched in February 2026, functioned as a subscription service for cybercriminals, charging a $1,500 setup fee and $500 per month. The platform specialized in device-code attacks, tricking users into authenticating on legitimate Microsoft login pages while secretly handing over their session tokens to attackers. This method effectively bypassed multi-factor authentication, allowing attackers to gain unauthorized access to email accounts.

The service also featured an AI chatbot designed for inbox analysis and fraud planning, enabling operators to scan emails for financial information and identify high-value targets within organizations.

Investigation and Takedown

The takedown operation was authorized by a US District Court, allowing Microsoft and its partners to seize 50 websites and disable more than 150 domains associated with EvilTokens. Coinbase's blockchain analysis team traced approximately $1.1 million in illicit revenue across four Tron addresses, mapping out over 700 distinct deposit addresses linked to the operation.

The geographic impact of the attacks was significant, with a concentration in the US, Canada, the UK, Australia, India, and France. The investigation revealed that around 1,000 cybercriminals utilized the EvilTokens service, generating an average of $1,100 in revenue per customer.

Implications and Recommendations

Microsoft and Coinbase's successful collaboration highlights the importance of public-private partnerships in combating cybercrime. The operation serves as a reminder of the evolving tactics used by cybercriminals, particularly the integration of AI in phishing schemes. Microsoft advises organizations to block device-code authentication where unnecessary and to implement strict measures for accounts suspected of compromise.

FAQ

What is EvilTokens?

EvilTokens is an AI-powered phishing-as-a-service platform that was responsible for compromising over 12,000 email inboxes across more than 10,000 organizations globally. It operated as a subscription service for cybercriminals.

How did EvilTokens operate?

EvilTokens functioned by charging a setup fee and a monthly subscription, allowing cybercriminals to perform device-code attacks that tricked users into authenticating on legitimate Microsoft login pages, thereby bypassing multi-factor authentication.

What was the outcome of the takedown operation?

The takedown operation led to the seizure of 50 websites and the disabling of over 150 domains associated with EvilTokens, as well as the arrest of two alleged operators in London on September 11, 2026.

What role did Coinbase play in the investigation?

Coinbase's blockchain analysis team traced approximately $1.1 million in illicit revenue linked to EvilTokens, mapping over 700 distinct deposit addresses and assisting in the overall investigation.

What recommendations did Microsoft provide to organizations?

Microsoft advised organizations to block device-code authentication where unnecessary and to implement strict measures for accounts suspected of compromise, highlighting the importance of vigilance against evolving cybercrime tactics.

Related

Comments

Comments are moderated before publish.

No comments yet — be the first.

Comment as guest

Captcha