Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Technology

UK police detain two suspects as Microsoft shuts down AI-driven EvilTokens phishing network

British authorities arrested two men alleged to have run the EvilTokens phishing service, while Microsoft seized more than 50 related websites.

A joint operation by UK law enforcement and Microsoft disrupted the EvilTokens phishing kit, which had been used to breach over 12,000 email inboxes across more than 10,000 organizations. On September 18, the Metropolitan Police Service arrested two men, aged 32 and 38, accused of managing the service’s website; they remain on bail pending further investigation. Microsoft seized 50 websites and disabled more than 150 related domains, working with Cloudflare, Coinbase, OpenAI and other partners.

Health-ISAC joined the lawsuit as a co-plaintiff because healthcare providers were among the targets. The operation marks the Digital Crimes Unit’s 40th court-authorized disruption and its first against an AI-enabled cybercrime service. Officials warned that compromised inboxes can be analyzed by AI within minutes, emphasizing the need for strong identity protections and independent verification of financial requests.

Why it matters

The takedown curtails a global phishing service that exploited AI to bypass security and steal from thousands of organizations.

In this story

EvilTokensphishingAI chatbotMFA bypassemail compromisearrestswebsite takedownMicrosofthealthcare targets
Get the beta ↗