Europe wants data centres to show their energy and water report card
22 September 2026
Investigators linked the platform to more than 12,000 compromised inboxes, showing how a stolen account can become a map for scams.
By Steve Carsley 23 September 2026
An email inbox contains more than messages. It can reveal who you trust, who pays you, which documents you handle and when somebody is expecting money. In the wrong hands, that everyday history can become a guide for fraud.
Microsoft said on September 22 that it and its partners had disrupted EvilTokens, a cybercrime service that used artificial intelligence to help criminals compromise accounts and plan scams.
In its announcement, also covered by CyberScoop, the company linked the platform to more than 12,000 compromised inboxes across over 10,000 organisations worldwide. Those figures are Microsoft’s findings. The company said affected sectors included healthcare, higher education and financial services.
Microsoft said the service could examine a stolen inbox, identify trusted relationships and help draft messages impersonating people the victim knew. The danger went beyond better spelling or a more polished greeting. The software could help criminals work out which requests might seem believable.
The company said the operation seized 50 websites and disabled more than 150 additional domains supporting the service. Two men were arrested in the UK on September 11 on suspicion of offences connected with the alleged operation, it said. Both were released on conditional police bail while the investigation continued.
An arrest is not a conviction. The September 22 announcement made the disruption public; it does not mean every part of the operation happened that day.
Microsoft’s separate technical investigation explains that EvilTokens abused device-code sign-in, a legitimate way to connect equipment such as a smart TV to an account.
Normally, someone enters a short code on another device to complete a sign-in they started. In these attacks, a deceptive message persuaded the victim to enter a code for a session controlled by the attacker. The person could unknowingly approve access without directly handing over a password.
That is why an official-looking page, or even a genuine sign-in page, is not enough on its own. The purpose of the request matters too. Microsoft recommends that organisations block this sign-in method where it is not needed.
CyberScoop reported that a Microsoft spokesperson estimated around 1,000 cybercriminals had used the service. Its reporting described a coordinated response involving technology companies, victim notifications and information shared with law enforcement.
BleepingComputer cautioned that the disruption does not eliminate this kind of threat and that similar services remain. It advised users to check which application they are authorising and stop if the request does not match an expected sign-in.
The everyday lesson is simple: a message can know a lot about you and still be dishonest. Before approving an unexpected login or a changed payment request, check it through a trusted route you already know.
Similar stories
22 September 2026
21 September 2026
20 September 2026