Analysis
Microsoft's Digital Crimes Unit dismantled the core infrastructure behind EvilTokens, an AI-powered phishing-as-a-service platform the company tracks internally as Storm-2992, according to Microsoft's own disclosure and corroborating reporting from SecurityWeek and SiliconANGLE. The action, obtained through a federal court order in the Eastern District of Virginia, seized 50 websites used to operate the service and disabled more than 150 additional supporting domains.
The Scale Of What Got Taken Down
EvilTokens hit more than 12,000 inboxes across 10,000 companies worldwide. Security firm SpyCloud, which assisted in the investigation, recovered 8,708 unique victim accounts spanning 6,585 corporate domains across 79 countries. Coinbase, one of the coordinating partners, traced roughly $1.1 million in revenue the operators collected in cryptocurrency between October 2025 and June 2026, spread across more than 700 different addresses on the Tron blockchain -- concrete financial forensics behind what's usually discussed only in the abstract.
“## The Scale Of What Got Taken Down EvilTokens hit more than 12,000 inboxes across 10,000 companies worldwide.”
The coordinated takedown spanned an unusually wide set of partners for a single action: Microsoft's Digital Crimes Unit worked alongside Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, the Shadowserver Foundation and TRM Labs. On the law-enforcement side, London's Metropolitan Police arrested two men, aged 32 and 38, on September 11 in connection with running the service's technical infrastructure -- a rare case of an AI-enabled cybercrime takedown producing named arrests rather than only infrastructure seizure.
This is Microsoft's fortieth legal seizure carried out by its Digital Crimes Unit in nearly two decades of activity, but the company frames it as the first aimed specifically at a criminal service built around artificial intelligence from the ground up, rather than one that merely used AI at some marginal stage of the operation -- distinguishing EvilTokens from the far larger universe of phishing kits that have incorporated AI-generated content as one feature among many.
The takedown is a concrete data point for the AI-security vendor category that's raised heavily this year. Cyera's $400 million extension and HiddenLayer's own $100 million Series B were both funded on the premise that enterprises need dedicated tooling against AI-native threats -- both to agents acting inside their own systems and, per this takedown, to AI-built attack infrastructure targeting them from outside. A criminal service built end-to-end around AI actually getting identified, seized and tied to named arrests is rarer validation than most vendor pitch decks can point to.
What the takedown doesn't resolve is scale: EvilTokens is one dismantled operation in a phishing-as-a-service market that has proliferated exactly because the barrier to building a new one keeps falling as AI tooling improves. Microsoft's own framing -- fortieth seizure in nearly 20 years, first AI-native one -- implicitly concedes this category is new enough that today's takedown methodology may not scale to the volume of similar services likely to follow.
For security-focused investors, the next signal worth watching is whether this coordination model -- a tech platform, a threat-intel firm, a crypto exchange and law enforcement working one case together -- becomes a repeatable template other AI labs and platforms adopt, or stays a one-off assembled for a single high-profile case.