Illustration for: Microsoft Dismantles First AI-Built Phishing Service

Microsoft Dismantles First AI-Built Phishing Service

Microsoft's Digital Crimes Unit dismantled EvilTokens, an AI-powered phishing service that hit more than 12,000 inboxes in 79 countries, calling it the first takedown of a criminal service built around AI rather than merely using it.

By the Numbers

12,000+
Inboxes hit
10,000
Companies affected
79
Countries
~$1.1M
Crypto revenue traced
40th
DCU seizure number
TC
By the Markets Desk
Edited by Trace Cohen · Early-stage VC & angel · Founder, New York Venture Partners
2 min read
ShareXLinkedInEmail

THE RUNDOWN

1

This is Microsoft's fortieth legal seizure by its Digital Crimes Unit in nearly two decades, but the first aimed specifically at a criminal service built around AI rather than one that used AI at some marginal stage.

2

SpyCloud recovered 8,708 unique victim accounts across 6,585 corporate domains in 79 countries, and Coinbase traced roughly $1.1M in cryptocurrency revenue across more than 700 addresses on the Tron blockchain -- concrete scale numbers behind the takedown.

3

The coordinated action spanned Microsoft, Coinbase, Cloudflare, OpenAI, Railway, SpyCloud, Health-ISAC, Shadowserver Foundation and TRM Labs, with UK Metropolitan Police arresting two men on September 11 -- a real cross-industry, cross-border enforcement model.

4

For AI-security-focused VCs, a criminal service built end-to-end around AI getting dismantled with named arrests and traced revenue is rarer concrete validation than most vendor pitch decks can point to.

TC

The VC Read · Trace's Take

Trace Cohen

The number that matters here isn't the seizure, it's the named arrests -- most AI-cybercrime stories end with infrastructure taken down and nobody held accountable, and this one didn't. Diligence item for anyone backing an AI-security vendor right now: ask which of their claimed threat detections have actually led to a takedown with this level of cross-industry coordination, because that's a much higher bar than a dashboard full of flagged anomalies.

Analysis

Microsoft's Digital Crimes Unit dismantled the core infrastructure behind EvilTokens, an AI-powered phishing-as-a-service platform the company tracks internally as Storm-2992, according to Microsoft's own disclosure and corroborating reporting from SecurityWeek and SiliconANGLE. The action, obtained through a federal court order in the Eastern District of Virginia, seized 50 websites used to operate the service and disabled more than 150 additional supporting domains.

The Scale Of What Got Taken Down

EvilTokens hit more than 12,000 inboxes across 10,000 companies worldwide. Security firm SpyCloud, which assisted in the investigation, recovered 8,708 unique victim accounts spanning 6,585 corporate domains across 79 countries. Coinbase, one of the coordinating partners, traced roughly $1.1 million in revenue the operators collected in cryptocurrency between October 2025 and June 2026, spread across more than 700 different addresses on the Tron blockchain -- concrete financial forensics behind what's usually discussed only in the abstract.

## The Scale Of What Got Taken Down EvilTokens hit more than 12,000 inboxes across 10,000 companies worldwide.

The coordinated takedown spanned an unusually wide set of partners for a single action: Microsoft's Digital Crimes Unit worked alongside Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, the Shadowserver Foundation and TRM Labs. On the law-enforcement side, London's Metropolitan Police arrested two men, aged 32 and 38, on September 11 in connection with running the service's technical infrastructure -- a rare case of an AI-enabled cybercrime takedown producing named arrests rather than only infrastructure seizure.

This is Microsoft's fortieth legal seizure carried out by its Digital Crimes Unit in nearly two decades of activity, but the company frames it as the first aimed specifically at a criminal service built around artificial intelligence from the ground up, rather than one that merely used AI at some marginal stage of the operation -- distinguishing EvilTokens from the far larger universe of phishing kits that have incorporated AI-generated content as one feature among many.

The takedown is a concrete data point for the AI-security vendor category that's raised heavily this year. Cyera's $400 million extension and HiddenLayer's own $100 million Series B were both funded on the premise that enterprises need dedicated tooling against AI-native threats -- both to agents acting inside their own systems and, per this takedown, to AI-built attack infrastructure targeting them from outside. A criminal service built end-to-end around AI actually getting identified, seized and tied to named arrests is rarer validation than most vendor pitch decks can point to.

What the takedown doesn't resolve is scale: EvilTokens is one dismantled operation in a phishing-as-a-service market that has proliferated exactly because the barrier to building a new one keeps falling as AI tooling improves. Microsoft's own framing -- fortieth seizure in nearly 20 years, first AI-native one -- implicitly concedes this category is new enough that today's takedown methodology may not scale to the volume of similar services likely to follow.

For security-focused investors, the next signal worth watching is whether this coordination model -- a tech platform, a threat-intel firm, a crypto exchange and law enforcement working one case together -- becomes a repeatable template other AI labs and platforms adopt, or stays a one-off assembled for a single high-profile case.

ShareXLinkedInEmail

Key Sources

2 sources

Reported by Microsoft · Analysis by Value Add Pulse.

← Back to Pulse

THE WIRE in your inbox— Tech, startup & VC news with Trace's take. Free, no spam.