• Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
Leaked Chainalysis Video Raises Concerns Over Monero Traceable Transaction Claim

Chainalysis sues US government over $94.66 million ICE contract awarded to TRM Labs

08/18/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
EvilTokens

Microsoft and Coinbase dismantle AI-powered phishing service that hit 12,000 inboxes across 10,000 companies

09/24/2026
Terra collapse

UST’s collapse explained: how a broken LUNA mechanism wiped out $40B and cost Do Kwon $4.5B

09/24/2026
Visa launches stablecoin advisory practice to guide global payments shift

Visa and Reap take stablecoin credit cards to 100+ markets, opening Europe, the Middle East and Africa

09/24/2026
  • Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
Leaked Chainalysis Video Raises Concerns Over Monero Traceable Transaction Claim

Chainalysis sues US government over $94.66 million ICE contract awarded to TRM Labs

08/18/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
EvilTokens

Microsoft and Coinbase dismantle AI-powered phishing service that hit 12,000 inboxes across 10,000 companies

09/24/2026
Terra collapse

UST’s collapse explained: how a broken LUNA mechanism wiped out $40B and cost Do Kwon $4.5B

09/24/2026
Visa launches stablecoin advisory practice to guide global payments shift

Visa and Reap take stablecoin credit cards to 100+ markets, opening Europe, the Middle East and Africa

09/24/2026
Thursday, September 24, 2026
  • Login
The Bit Gazette
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion
No Result
View All Result
The Bit Gazette
No Result
View All Result
Home Ai News

Microsoft and Coinbase dismantle AI-powered phishing service that hit 12,000 inboxes across 10,000 companies

A joint Microsoft-Coinbase investigation has exposed how an AI-powered phishing service scaled business email compromise across thousands of organizations before its infrastructure was disrupted.

by Elizabeth Omotoke
26 minutes ago
in Ai News
Reading Time: 4 mins read
0
EvilTokens

EvilTokens

Share on FacebookShare on Twitter

Microsoft and Coinbase have dismantled EvilTokens, a subscription-based phishing-as-a-service platform that used AI to compromise more than 12,000 email inboxes across 10,000-plus organizations worldwide since February 2026, and traced roughly $1.1 million in proceeds through crypto payments before two men were arrested in the U.K.

Microsoft said the service was designed to make business email compromise faster and easier by bringing account compromise, mailbox analysis, reconnaissance and fraud preparation into one subscription-based platform. Customers could reportedly access the service through Telegram after paying a $1,500 initial fee and $500 monthly subscription.

The scale of the operation was amplified by artificial intelligence. Instead of forcing attackers to manually read hundreds or thousands of messages after compromising an account, the platform could summarize and translate emails, identify trusted contacts, map organizational roles and locate conversations involving invoices or wire transfers.

Microsoft Digital Crimes Unit executive Steven Masada said the platform’s AI went beyond simply generating phishing emails. It could help criminals determine “who to target, who to impersonate” and how to exploit trusted relationships to pursue fraud EvilTokens.

EvilTokens exploited legitimate Microsoft authentication

At the center of the operation was an abuse of Microsoft’s device-code authentication process.

Device-code authentication is a legitimate feature intended for devices with limited interfaces, including smart TVs, printers and conferencing equipment. In a normal scenario, a user receives a code and enters it through a browser to authenticate a legitimate device.

Attackers instead initiated the authentication request and embedded the resulting code into convincing phishing campaigns. Victims were directed to Microsoft’s legitimate login page and persuaded to enter the code, unknowingly authorizing a session controlled by the attacker. Microsoft said the technique allowed criminals to obtain authenticated access without directly stealing the victim’s password.

The phishing messages used familiar business themes, including invoices, shared documents, requests for proposals and other routine communications. Microsoft identified 44 different themes used by the service and said the campaigns employed malicious URLs, PDF attachments and HTML files.

Once inside an inbox, EvilTokens could help attackers identify employees with financial authority, discover payment-related conversations and determine which trusted individuals could be impersonated. In some cases, attackers also created malicious inbox rules or registered devices to maintain access.

Microsoft tracks the threat actor behind the development and support of the platform as Storm-2992.

Coinbase follows the crypto money trail

The investigation took another turn when Coinbase’s Global Intelligence team began following the cryptocurrency payments associated with EvilTokens.

Coinbase said it traced approximately $1.1 million in platform revenue across four Tron addresses between October 2025 and June 2026. Investigators identified more than 1,000 deposits from over 700 distinct addresses and followed the movement of funds from payments into the service through to eventual cash-out destinations.

The $1.1 million figure represents revenue generated by the alleged phishing service, rather than the total amount stolen from its victims.

Coinbase said its investigators combined blockchain transaction data with test transactions, merchant records, device information and open-source intelligence to help identify the alleged operators. The findings were then referred to London’s Metropolitan Police.

The crypto exchange also investigated customers it identified as purchasers of the service and referred relevant cases to law enforcement. Coinbase said its evidence supported Microsoft’s civil action, which resulted in the seizure of 50 websites and the disabling of more than 175 domains connected to the operation.

Coinbase customers were also affected indirectly. The exchange said some users were manipulated through compromised email conversations into sending cryptocurrency to scam-controlled addresses, although Coinbase accounts and credentials themselves were not compromised.

Takedown exposes the next phase of AI-enabled cybercrime

The disruption involved a broad coalition of technology companies, security organizations and law enforcement agencies. Microsoft said the operation was authorized by the U.S. District Court for the Eastern District of Virginia and involved partners including Coinbase, Cloudflare, OpenAI, Railway, SpyCloud, the Shadowserver Foundation, TRM Labs and Health-ISAC.

British authorities also arrested two men, aged 32 and 38, on September 11 in connection with the alleged operation. Microsoft said both were subsequently released on police bail while the investigation continues.

The case demonstrates why cryptocurrency tracing has become an increasingly important component of cybercrime investigations. Blockchain transactions can leave a financial trail even when criminals operate through pseudonymous addresses and online identities.

It also highlights a broader concern around AI and cybercrime. EvilTokens did not merely automate the creation of deceptive messages; it helped attackers interpret compromised data and turn that information into targeted fraud strategies. Microsoft investigators also found evidence that portions of the platform itself were built with AI-assisted coding tools.

Coinbase said the operator had indicated plans to expand the toolkit toward Gmail and Okta accounts, suggesting the underlying business model could extend beyond Microsoft environments.

Microsoft recommends that organizations restrict device-code authentication where it is not required, revoke refresh tokens following suspected compromise and force affected users to reauthenticate. Coinbase separately advises organizations to independently verify changes to payment instructions and use phishing-resistant authentication such as passkeys or hardware security keys.

The infrastructure behind EvilTokens has now been disrupted, but the techniques it exposed remain relevant. For security teams, the immediate challenge is not simply removing malicious domains; it is detecting whether stolen sessions, tokens and inbox access survived the takedown.

Tags: . crypto newsAI-powered phishingcoinbasecrypto SecurityCryptocurrency Newscybercrimecybersecurityemail securityMicrosoftphishing attackphishing service
Share198Tweet124
Elizabeth Omotoke

Elizabeth Omotoke

  • Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
Leaked Chainalysis Video Raises Concerns Over Monero Traceable Transaction Claim

Chainalysis sues US government over $94.66 million ICE contract awarded to TRM Labs

08/18/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
EvilTokens

Microsoft and Coinbase dismantle AI-powered phishing service that hit 12,000 inboxes across 10,000 companies

09/24/2026
Terra collapse

UST’s collapse explained: how a broken LUNA mechanism wiped out $40B and cost Do Kwon $4.5B

09/24/2026
Visa launches stablecoin advisory practice to guide global payments shift

Visa and Reap take stablecoin credit cards to 100+ markets, opening Europe, the Middle East and Africa

09/24/2026
The Bit Gazette

Copyright © 2025 - The Bit Gazette.

Navigate Site

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Follow Us

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion

Copyright © 2025 - The Bit Gazette.