Microsoft Takes Down AI‑Powered Phishing Service ‘EvilTokens’; Two Suspects Arrested in the UK
What Happened – Microsoft’s Digital Crimes Unit obtained a court order to shut down the “EvilTokens” AI‑chatbot, a subscription‑based service that sold cybercriminals automated phishing playbooks. Working with the U.K. Metropolitan Police, the operation led to the arrest of two alleged operators.
Why It Matters for Trust & Control Assurance
- The case illustrates the risk of malicious third‑party services that can be weaponized against any organization’s users. Continuous monitoring of external threat‑as‑a‑service providers is a core control‑assurance activity.
- Evidence of the takedown (court filings, arrest records) provides a defensible audit trail that demonstrates due diligence in vendor oversight and fraud‑prevention programs.
Who Is Affected – Health‑sector groups (partnered with Health‑ISAC), financial services, and any enterprise that relies on email communications for business processes.
Recommended Actions
- Review your third‑party risk program to include monitoring of AI‑enabled malicious services and phishing‑as‑a‑service platforms.
- Capture and retain evidence of any investigations, legal actions, or threat‑intel reports related to such services to support audit readiness.
Technical Notes – EvilTokens operated via a Telegram bot, charging a $1,500 onboarding fee plus $500 monthly. It leveraged multiple AI models (including OpenAI) to analyze breached inboxes, map victim relationships, and auto‑generate fraudulent messages. Source: The Record