Microsoft's Digital Crimes Unit, working with Coinbase and six other partners, has dismantled EvilTokens — a subscription-based phishing service that Microsoft says used artificial intelligence "at every step of the attack chain" — in a court-authorized seizure announced Tuesday.

The action, carried out under authorization from the US District Court for the Eastern District of Virginia, seized 50 websites tied to EvilTokens and disabled more than 175 associated domains, Fortune reported. Microsoft says the service was linked to roughly 12,000 compromised inboxes and targeted organizations ranging from real estate firms to banks and healthcare providers, The Hacker News reported.

How the Scheme Worked

EvilTokens operated as a phishing-as-a-service offering built around device-code phishing — a technique that abuses OAuth device authorization flows. Victims are prompted to enter a code on a legitimate login page, and once they approve, the attacker's session token grants access without ever touching a password or second factor. Microsoft said the operators used AI to generate convincing lures, personalize messages and automate the attack workflow end to end.

The crypto connection runs deeper than the toolkit. Coinbase participated in the investigation and traced approximately $1.1 million in revenue to the operation through blockchain analysis, Fortune reported. Partners in the takedown included Health-ISAC, Cloudflare, OpenAI, Railway, SpyCloud, The Shadowserver Foundation and TRM Labs — a coalition spanning infrastructure providers, threat-intelligence firms and the crypto industry's own forensics arm.

Arrests in London

In a parallel criminal element of the investigation, British police arrested two suspected operators of the service in London on September 18, according to Fortune. The suspects' identities have not been publicly confirmed, and the allegations against them remain unadjudicated.

Axios reported that the takedown fits Microsoft's broader playbook of using civil court orders to dismantle criminal infrastructure faster than criminal prosecution allows — seizing domains and servers first, prosecuting individuals where possible.

Why It Matters for Crypto

Device-code phishing is a direct threat to exchange accounts and web wallets: a stolen session token can bypass password and two-factor protections entirely, and AI-generated lures have made the attacks dramatically harder to spot. The EvilTokens case is also a template for defense — a traditional tech company, a crypto exchange and blockchain-analytics specialists pooling telemetry to map both the infrastructure and the money.

CSO Online noted that the operation illustrates how quickly AI-enabled cybercrime has industrialized — and how the countermeasures now require the same combination of legal process and cross-industry coordination.

For crypto users, the defensive lesson is unchanged but newly urgent: approve device sign-in prompts only when you initiated them, treat unexpected verification codes as a warning rather than a step, and prefer hardware-key authentication where platforms support it — session-token theft works far less reliably against phishing-resistant factors.

TrustGrade tracks platform security posture and verified incident data. trustgrade.ai.