The AI Read
← Latest
Afternoon Brief · September 22nd 2026

Afternoon Brief, September 22nd 2026

Microsoft disclosed a court-authorized takedown of EvilTokens. The service used AI to turn stolen inboxes into fraud plans. British police arrested two suspected operators earlier this month.

2 min read·Editorial by Elias Marchetti

Microsoft disrupts an AI service that turned stolen inboxes into fraud plans

Microsoft disclosed the disruption of EvilTokens, a subscription cybercrime service whose chatbot analyzed stolen email to identify payment authority, trusted contacts and opportunities for impersonation. The company estimates that the service compromised more than 12,000 inboxes across over 10,000 organizations.

Microsoft says it and its partners seized 50 websites and disabled more than 150 supporting domains under a court-authorized operation. British police arrested two suspected operators on September 11th; both were released on conditional bail while the investigation continues. Today's development is the public disclosure of the disruption, not a claim that the arrests happened today.

The case extends AI-assisted fraud beyond drafting convincing messages: the service helped customers decide whom to impersonate and which payments to target. The compromise totals are Microsoft's estimates. The takedown does not establish that stolen mailbox contents have been recovered or that every customer of the service has lost access to them. SourcesAB

Sources

4 citations · 2 primary · 2 secondary