Download Privacy Needle App

Type to search

Cybersecurity

Microsoft Disrupts AI-Powered Phishing Platform and Arrests Suspects

Share

Microsoft has disrupted EvilTokens, an artificial intelligence-driven phishing platform that compromised more than 12,000 email accounts across 10,000 organisations globally.

The platform, which emerged in February 2026, leveraged AI to automate the entire attack chain. This included using AI to draft highly customised social engineering messages and to identify high-value targets within victim inboxes. Microsoft believes the platform itself may have been coded using AI, offering 44 different themes for malicious emails and phishing pages.

Attackers primarily utilised device code phishing to gain unauthorised access. This technique exploits authentication flows designed for devices that do not support standard login methods, such as smart TVs or printers. By tricking a user into entering a code provided by the attacker into a browser session, the threat actors could obtain access tokens. This method allowed for persistent access to accounts without the attackers ever needing to obtain a password.

The scale of the EvilTokens phishing disruption highlights the growing complexity of AI-assisted cybercrime. The impact was felt in the United States, Canada, the United Kingdom, Australia, India, and France.

In a coordinated effort involving partners such as OpenAI, Cloudflare, and SpyCloud, Microsoft seized 50 websites and disabled more than 150 domains associated with the platform’s infrastructure. The disruption was supported by several other organisations, including TRM Labs, Coinbase, and the Shadowserver Foundation.

Two men, identified in a Microsoft complaint as Felix Utomi and Waidi Segun Adams, have been arrested in the United Kingdom in connection with the operation. The legal complaint also names five other unnamed individuals suspected of involvement.

To use the service, cybercriminals were required to pay an initial access fee of $1,500, followed by a $500 monthly subscription.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.