Microsoft says it helps disrupt “EvilTokens,” an AI-powered phishing-as-a-service used by cybercriminals to compromise business email accounts at scale. According to Microsoft’s reporting, the platform used automated techniques and prebuilt phishing templates, while also using AI to analyze victims’ inboxes to identify high-value targets and to tailor lures for specific recipients.

Microsoft and partners coordinated actions that included seizing infrastructure and disabling domains used to operate the service. The reporting describes evidence that EvilTokens operated through a commercially packaged offering, with capabilities that spanned account compromise, mailbox-based targeting, and fraud preparation. Microsoft also says it notified affected customers, supported remediation, and shared intelligence with law-enforcement partners.

Different outlets emphasize different parts of the disruption. Slashdot highlights the scale of compromised inboxes and the platform’s end-to-end automation, including target selection and impersonation based on relationships inside organizations. SecurityWeek focuses on the platform’s use of AI across the attack chain, including social engineering message creation and determining who to target.

Microsoft says operational action in the United Kingdom followed intelligence sharing, including arrests in connection with the investigation.