# AI-Powered Phishing as a Service: The Disruption of the EvilTokens Operation
A landmark operation led to the dismantling of EvilTokens, a commercial phishing service that leveraged artificial intelligence to compromise email accounts and orchestrate large-scale financial fraud. The takedown, executed with authorization from a U.S. District Court, marked a significant victory in the ongoing battle against Phishing-as-a-Service (PhaaS) platforms, which increasingly lower the barriers for aspiring cybercriminals.
The scheme fundamentally exploited the OAuth 2.0 device authorization flow, a legitimate authentication method used by major technology providers. Victims were deceived into entering a malicious device code on a legitimate sign-in portal. Once the code was submitted, the attacker received access and refresh tokens, granting them continuous entry into the victim’s email without ever needing their actual password. Crucially, this unauthorized access often persisted even after a password reset, as the stolen session tokens remained active unless explicitly revoked.
What truly distinguished EvilTokens was its deep integration of AI. At the core of the platform was an AI chatbot capable of analyzing a compromised inbox. It could identify trusted contacts, pinpoint pending financial transactions, and highlight sensitive organizational responsibilities. The AI could then automatically draft messages impersonating these trusted individuals, guiding victims toward fraudulent payments or data leaks. The toolkit was even developed with the assistance of AI—often referred to as “vibe coding”—making it highly sophisticated while potentially lowering the technical skill required to operate it.
The platform was marketed on encrypted messaging applications and operated under a tiered commercial model. Subscribers paid recurring monthly fees for continued access, with one-time purchases ranging from $600 for a bulk sender tool to $1,500 for the core device code phishing link. This turnkey solution included customer support, management dashboards, and auxiliary tools to automate business email compromise (BEC) workflows across the globe.
Financial investigators traced approximately $1.1 million in cryptocurrency revenue linked to the service across multiple blockchain addresses, with deposits coming from over 700 distinct sources. The scale of the compromise was staggering: the operation was tied to more than 12,000 compromised inboxes across over 10,000 organizations worldwide, with victim activity concentrated in the United States, Canada, the United Kingdom, Australia, India, and France. Targeted sectors included wholesale distribution, construction, financial services, real estate, higher education, and healthcare.
The disruption involved a broad coalition of public and private sector partners. Authorities with the Metropolitan Police Service arrested two men, aged 32 and 38, on September 11, 2026, in connection with the illicit commercial operation. Technology firms and cybersecurity organizations collaborated to seize 50 websites and disable over 150 associated domains. One partner organization recaptured phished data tied to more than 8,700 unique victim accounts spanning nearly 6,600 corporate domains across 79 countries. The threat actors behind the service were designated as Storm-2992.
### Frequently Asked Questions (FAQ)
**Q: How does device code phishing differ from traditional phishing?**
A: Traditional phishing typically aims to steal usernames and passwords directly through fake login pages. Device code phishing bypasses this by leveraging legitimate authentication flows. The victim is tricked into entering a code on a real, official website (like the provider’s device login page). This legitimate action generates authentication tokens for the attacker, granting them session access without the victim ever exposing their actual password.
**Q: What specific role did artificial intelligence play in the EvilTokens platform?**
A: AI was embedded throughout the attack lifecycle. After an inbox was compromised, AI analyzed the victim’s emails to map out organizational structures, identify financial discussions, and find trusted relationships. It then used this data to automate the creation of highly convincing impersonation messages, drafting fraud strategies and targeting the most lucrative victims automatically.
**Q: Who were the victims of EvilTokens?**
A: The service indiscriminately targeted a wide range of organizations. The highest concentrations of victim activity were found in the United States, Canada, the United Kingdom, Australia, India, and France. Businesses targeted included wholesale distributors, construction firms, financial institutions, real estate agencies, healthcare providers, and universities.
**Q: What happened to the operators of EvilTokens?**
A: Law enforcement authorities, specifically the Metropolitan Police Service, arrested two men—aged 32 and 38—in connection with the illicit commercial operation. The digital infrastructure supporting the service was also dismantled through the seizure of websites and the disabling of numerous domains.
### Conclusion
The dismantling of EvilTokens highlights a critical evolution in cybercrime: the democratization of sophisticated attacks through AI and subscription models. By turning complex identity theft and business email compromise into accessible, turnkey services, platforms like EvilTokens pose an outsized threat to global cybersecurity. The successful collaboration between law enforcement and the private sector serves as a crucial reminder that disrupting these ecosystems requires a unified, multifaceted response. As AI continues to advance, so too must the defensive strategies used to protect digital identities and financial systems.
Thank you for reading



