By Sinisa Markovic
Publication Date: 2026-09-23 08:34:00
The EvilTokens phishing service, which compromised more than 12,000 inboxes at over 10,000 organizations, has been disrupted by a coalition of law enforcement and private-sector partners led by Microsoft.
With authorization from the US District Court for the Eastern District of Virginia, Microsoft and Health-ISAC worked with Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation and TRM Labs to seize 50 websites used to operate the service and disable more than 150 domains tied to its infrastructure.
Seizure notice (Microsoft)
Microsoft notified affected customers, helped them remediate compromised accounts and shared intelligence to support further investigation.
“No single organization could disrupt EvilTokens alone. The service relied on hosting providers, cloud services, AI tools, financial services, and other online resources that cybercriminals repurposed to support fraud at scale,” said Steven Masada, Associate General Counsel and GM,…



