Who's involved
- Microsoft
- The company that makes Windows, Outlook and the real sign-in page where victims typed the code.
- Its own sign-in feature was used to open the mailboxes. It investigated the service, took it to court, and published nearly every number in this story.
- Steven Masada
- The Microsoft lawyer who runs its Digital Crimes Unit, the group that brings these cases.
- Signed Microsoft's published account of the takedown, the source of most figures in this story.
- Telegram
- A messaging app whose channels can be run like storefronts.
- The service was introduced and sold there, at $1,500 to join and $500 a month. Neither source reports any action by Telegram.
- Ars Technica
- A technology news site with its own security desk.
- It is the only source here for how the sign-in trick worked end to end, and for how much mail the service could read at once.
- Metropolitan Police Service
- London's police force.
- Its cybercrime team arrested two men on September 11, after Microsoft shared intelligence with it. Both were released on police bail.
What changed
EvilTokens was a cybercrime service you could subscribe to. It charged $1,500 to join and $500 a month after that, on the messaging app Telegram, whose channels can be run like storefronts. What the money bought was a way into other people's email and an AI that read what it found there. Microsoft says the service launched in February 2026 and within months was linked to more than 12,000 compromised inboxes across over 10,000 organizations. The heaviest victim activity was in the United States, then Canada, the United Kingdom, Australia, India and France. The organizations ranged from wholesale distribution and construction to financial services, real estate, higher education and healthcare.
The break-in did not use a stolen password. It used device code authentication, a real Microsoft sign-in feature. Ars Technica, the technology news site, reports how it works. It is built for televisions and other devices with no keyboard: the screen shows a short code and tells you to type it into a browser somewhere else. EvilTokens generated that code for the attacker, then steered the victim to Microsoft's own legitimate sign-in page to enter it. The victim completed a genuine sign-in. The device that got enrolled belonged to the attacker. Microsoft says victims unknowingly gave criminals access to their email accounts without revealing their passwords.
What the subscription bought was the reading. Microsoft says that once inside an account, criminals have traditionally needed time and experience to sift through thousands of messages, identify decision-makers, understand payment processes and find opportunities for fraud. EvilTokens began automating that work. Ars Technica reports the platform analyzed 5,000 compromised emails at a time. Preset prompts offered to find wire-transfer discussions and to locate vendor invoices. Others offered to identify the organization's "money movers" and determine the best people to impersonate.
Microsoft published its account of all this on September 22. It says the disruption combined a civil court case with operational work alongside industry partners and police. With authorization from a federal court in Virginia, Microsoft and its partners seized 50 websites used to operate the service and disabled more than 150 further domains. In the United Kingdom, London's police force, the Metropolitan Police Service, arrested two men aged 32 and 38 on September 11. Microsoft says it shared intelligence with that force's cybercrime team, which let its officers act. Both men were released on police bail subject to conditions. No charge and no conviction has been reported.
What's at Stake
What EvilTokens charged each month, after a $1,500 fee to join.
Market intelligence
The read: Over five years, Microsoft is up 66.3%. Over one year, Microsoft is down 2.6%. Over the past month, Microsoft is up. Microsoft is down 0.5% today, behind the Nasdaq Composite's +0.0%.
Steven Masada, Telegram, Ars Technica and Metropolitan Police Service don't trade on a stock market.
Prices move for many reasons. This shows where they stand, not what caused it.
Prices: Yahoo Finance.
The System Underneath
A criminal paid a subscription, borrowed a real sign-in shortcut to open a mailbox, and let an AI read it to find whoever can move the money.
The People
- A real sign-in shortcutDevice code authentication is built for televisions and devices with no keyboard. The screen shows a short code and asks you to type it in a browser somewhere else.
- completedTyped a genuine code on a genuine pageThe service made the code for the attacker and steered the victim to Microsoft's own sign-in page to enter it. Microsoft says victims gave access without revealing their passwords.
- automatedThe readingArs Technica reports the platform analyzed 5,000 compromised emails at a time. Preset prompts offered to find wire-transfer talk, the money movers, vendor invoices and the best people to impersonate.draftedThe impersonationMicrosoft says the platform could recommend fraud strategies, including drafting messages that impersonated trusted contacts.
- sentA request to move moneyMicrosoft says the platform could draft messages that impersonated trusted contacts, to get victims to take action. The person who can move funds receives one of them.
- confirmsA check another wayMicrosoft's own instruction: independently verify requests to change payment information, redirect funds or approve unusual transactions through a trusted second channel. In plain terms, that means a route other than the email that asked.
- seizedA court order and 50 seized websitesWith authorization from a federal court in Virginia, Microsoft and its partners seized 50 websites running the service and disabled more than 150 further domains.
The middle of this chain happens inside a mailbox, where the owner cannot see it. The two steps that break it, a check another way and a court order, both happen outside.
How We Got Here
- The service opens
Microsoft says EvilTokens launched this month, and Ars Technica reports it was introduced over a Telegram channel. Neither source gives a day.
- Two arrests in the United Kingdom
London's Metropolitan Police Service arrested two men, aged 32 and 38, and seized digital devices. Both were released on police bail subject to conditions while the investigation continues.
- The takedown is published
Microsoft publishes its account, naming 50 seized websites, more than 150 disabled domains, and more than 12,000 compromised inboxes across over 10,000 organizations.
Why it matters
Here is why the reading was the product. A stolen mailbox is not money. It is a pile of messages, and turning that pile into a wire transfer is slow, skilled work. Find whoever approves payments. Find who they answer to. Find a vendor whose invoice nobody would question. Then write a message that sounds like someone that person already trusts. Microsoft's own description is that this traditionally took time and experience. EvilTokens sold that time as a subscription, with customer support and a management dashboard.
The reading only works while the access lasts. Microsoft says that access could persist even after a password reset if the associated sessions and tokens were not also revoked. A password is the answer you give at the door. A session token is the wristband you are handed once you give it. Changing the password does not take the wristband back. That is why the account is not clear until those existing logins, the sessions and tokens, are revoked too.
The instruction Microsoft ends on is small enough to use this week and it costs nothing. Independently verify requests to change payment information, redirect funds or approve unusual transactions through a trusted second channel. Neither source says what counts as one. The working reading is a phone number you already had, not one printed inside the message asking you to pay. It works for one reason, and the reason is the whole story: the attacker is sitting inside the email. The attacker is not sitting inside the phone call.
That instruction is Microsoft's, and so is nearly everything else in this story. The company is three things at once here: the vendor whose sign-in feature was used, the investigator that measured what happened, and the publisher of the figures. The count of more than 12,000 inboxes is its own, not an independent audit. That does not make it wrong. It does mean you are taking the company's word for it.
Who's Accountable

Steven Masada signed Microsoft's account of the takedown. Nearly every number here is the company's own count.
Photograph: Institute for Security and TechnologyWhat to watch
Nothing here is finished, and Microsoft says so in its own words. The infrastructure supporting EvilTokens has been disrupted, it writes, but the model it demonstrated will not disappear with it. Two men were arrested and released on police bail subject to conditions. No charge has been reported, no conviction has been reported, and nothing about the case has been decided.
Steven Masada signed the account, as Associate General Counsel and General Manager of Microsoft's Digital Crimes Unit. That is the group inside the company that brings civil cases like this one. Microsoft says the action was that unit's 40th court-authorized disruption and its first against an end-to-end AI-enabled cybercrime service. Both of those counts are Microsoft's own, and no second source carries them.
The thing worth carrying is not the name of one service. It is that two ordinary conveniences were rented out together. One was a sign-in shortcut built so that a television could log you in. The other was an assistant that reads a mailbox and tells you what matters in it. Neither was broken. Both worked exactly as designed, for somebody else.



Reader comments
Not signed in yet — hit Post and we'll finish it together