UK police arrest two over AI-assisted EvilTokens phishing service
UK police arrested two men suspected of administering EvilTokens, an AI-enabled phishing service, while Microsoft and its partners seized more than 50 related websites and disabled over 150 supporting domains. The operation aims to disrupt a service that enabled criminals to bypass multi-factor authentication and access Microsoft 365 accounts, highlighting the growing risks posed by AI-assisted cybercrime.
EvilTokens reportedly compromised more than 12,000 email inboxes across over 10,000 organisations worldwide after launching in February 2026. Its AI chatbot helped attackers analyse inboxes, identify valuable targets and devise fraud strategies; the two suspects, aged 32 and 38, were released on bail, while Microsoft notified affected customers and helped secure their accounts.
- Two UK suspects arrested over EvilTokens administration.
- More than 50 websites seized and 150 domains disabled.
- AI-assisted phishing compromised 12,000-plus inboxes worldwide.
Cybersecurity Technology UK World
Read the full article at the source →
Originally published by The Register as “UK cops arrest 2 EvilTokens suspects, Microsoft seizes 50 phishing kit websites”.