cd /news/artificial-intelligence/microsoft-and-coinbase-take-down-evi… · home topics artificial-intelligence article
[ARTICLE · art-137274] src=startupfortune.com ↗ pub= topic=artificial-intelligence verified=true sentiment=↓ negative

Microsoft and Coinbase Take Down EvilTokens, an AI Phishing Service

Microsoft's Digital Crimes Unit, acting on authorization from the US District Court for the Eastern District of Virginia, seized 50 websites and disabled more than 150 domains tied to EvilTokens, an AI-powered phishing subscription service that compromised 12,000 email inboxes across more than 10,000 organizations since launching in February, Microsoft said in a September 22 account of the takedown. London's Metropolitan Police arrested two men, ages 32 and 38, on September 18 on suspicion of administering the service, which charged a $1,500 signup fee plus $500 a month and used an AI chatbot to map reporting lines and flag employees who approved wire transfers, while Coinbase traced subscriber cryptocurrency payments to estimate about $1.1 million in total revenue. Microsoft tracks the group behind EvilTokens internally as Storm-2992.

by read5 min views3 publishedSep 22, 2026
Microsoft and Coinbase Take Down EvilTokens, an AI Phishing Service
Image: Startupfortune (auto-discovered)

Microsoft and Coinbase just dismantled a phishing subscription service that used an AI chatbot to pick which employee at a company to scam, and it took a federal court order, two arrests in London and blockchain tracing to shut it down.

EvilTokens didn't hide in some dark corner of the internet. It ran a storefront on Telegram, charged a $1,500 signup fee and $500 a month after that, and promised subscribers something no ordinary phishing kit could: an AI 'analyst' that read through a hacked inbox, mapped who trusted whom inside the company, and told the criminal exactly which employee controlled the money.

Since the service launched in February, it compromised 12,000 email inboxes across more than 10,000 organizations, according to Microsoft's Digital Crimes Unit, which published its account of the takedown on September 22. Wholesale distributors, construction firms, banks, real estate companies, universities and hospitals all turned up among the victims. Microsoft tracks the group behind it internally as Storm-2992.

That's not a hobbyist operation. That's a business.

EvilTokens ran on device-code phishing, a technique that abuses a legitimate Microsoft sign-in flow instead of stealing a password outright. A victim gets tricked into entering a code on a real Microsoft login page, which hands the attacker a working authentication token, multi-factor authentication included. From there, the AI component did the sorting work a human criminal used to do by hand: it combed the compromised inbox, mapped reporting lines and vendor relationships, flagged who approved wire transfers, and ranked which contacts were the highest-probability marks for a follow-up fraud email.

Cloudflare Launches Wallets That Let AI Agents Autonomously Hold and Spend Money Cloudflare launched Cloudflare Wallets on August 4, letting AI agents hold stablecoins and autonomously pay for APIs through the x402 protocol, with spend limits set by human account owners. The move builds on Cloudflare's October 2025 Trusted Agent Protocol deal with Visa and lands amid a broader fight between Visa, Mastercard, Stripe, and... - AI agents autonomous wallet payments - Cloudflare wallets for AI spending

The chatbot didn't write the phishing lure itself. It picked the victim after the door was already open, the part of the job that separates a low-yield spam blast from a six-figure wire fraud.

Device-code phishing isn't new, but 2026 has been the year it went mainstream. Researchers at the Cloud Security Alliance tracked a single device-code campaign that hit more than 340 Microsoft 365 organizations back in March, and researchers at Push Security have charted a steady climb in the technique's use since. EvilTokens didn't invent the exploit. It industrialized it, wrapping the same authentication trick in a subscription, a support channel and, eventually, an AI feature.

A Court Order, Two Arrests and Coinbase's Ledger Work #

London's Metropolitan Police arrested two men, ages 32 and 38, on September 18, accusing them of administering the EvilTokens website. Both were released on bail while the investigation continues. Microsoft, acting on authorization from the US District Court for the Eastern District of Virginia, seized 50 websites tied to the operation and disabled more than 150 domains built to run it.

Coinbase's role was narrower but specific: tracing the money. The exchange's investigators followed the cryptocurrency payments subscribers used to pay their monthly fee and put a number on the operation's take, about $1.1 million in total revenue. That figure came from blockchain analysis, not a raid on a server room. It's the kind of forensic work crypto exchanges increasingly get pulled into when the wallet address on the other end turns out to belong to enterprise phishing rather than a scam coin.

Microsoft didn't do this alone, either. Cloudflare, OpenAI, Railway, SpyCloud, the Shadowserver Foundation and the Health-ISAC information-sharing group all fed into the takedown, each supplying a different piece: hosting data, abuse signals, or threat intelligence.

Microsoft's Digital Crimes Unit has now run 40 of these court-authorized disruptions over nearly two decades, dating back to early botnet takedowns. But according to Steven Masada, the unit's associate general counsel and general manager, this is the first time it has gone after an end-to-end AI-enabled cybercrime service, meaning the AI wasn't a feature bolted onto the crime somewhere along the way. It was the product.

Frankly, that distinction matters more than the arrest count. A phishing kit is a piece of software. A phishing kit with a built-in analyst that gets better at picking victims is a business model, and this is the first time anyone has had to take one apart in court.

Brian Armstrong tells crypto founders who pivoted to AI they got it backwards Coinbase CEO Brian Armstrong published a pointed July 27 rebuttal to crypto founders who pivoted to AI, coining the term 'AiFi' (Agentic Finance) and arguing the two industries are structurally dependent. His evidence: Coinbase's x402 protocol has processed over 100 million machine-to-machine transactions in nine months. Armstrong's core argument... - crypto founders pivoting to AI - payment infrastructure for AI agents

Also read: OpenAI and Microsoft Staff Privately Called Their Own AI an Existential Threat to NewsNscale Files for a $35 Billion IPO That Tests the Neocloud StoryDario Amodei will ask the UN Security Council to slow down the AI race this week

This article is posted in AI News, check it out for more related stories.

Join the discussion #

Open in the community → Almost there. Sign in and your reply posts straight away.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @microsoft 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/microsoft-and-coinba…] indexed:0 read:5min 2026-09-22 ·