Caraway’s $495 coffee maker is designed to keep plastic out of your morning cup of joe
Microsoft and Coinbase help take down ‘EvilTokens’ phishing network
We’ve all seen the emails: A spoofed message from your company’s CFO or a vendor asking you to pay an outstanding invoice. These phishing messages lead to millions of dollars of fraudulent payments every year, and are becoming more realistic all the time. The good news is companies are fighting back: On Tuesday, Microsoft and Coinbase announced they had taken down a phishing network, known as EvilTokens, that has defrauded businesses ranging from real estate firms to banks to healthcare providers.
In a blog post describing the scam, the companies explained that EvilTokens sold a do-it-yourself phishing kit over Telegram designed to exploit Microsoft Outlook email accounts. The kit came with a sinister feature, described by the post as “an AI-powered analyst that mapped trusted relationships, identified who controlled payments, and flagged where fraud was most likely to succeed.”
This meant that, once a victim fell for a phishing email, scammers could use the AI analyst to create especially persuasive emails to target those in position to pay. This is a notable evolution from conventional phishing campaigns, which have typically relied on a “spray and pray” approach to luring victims.
The EvilTokens tool also proved hard to dislodge. As the blog post explained, the phishing campaigns included links directing victims to fake Microsoft or DocuSign pages that displayed a code, and instructed them to enter it on a legitimate Microsoft website to verify their identity. If they did so, EvilTokens was able to bypass two-factor authentication and stay hidden on their computers—even surviving password resets.
The software powering the EvilTokens kit represents a sophisticated evolution of conventional phishing tools but, according to Coinbase’s security team, the most alarming attribute is that it requires few technical skills to use it.
“It completely obliterates the barrier to entry on phishing as a service, and can be operated on an industrial scale,” said Charlotte Surrey, an investigator on Coinbase’s global intelligence team. She added that the EvilTokens kit sold on Telegram for between $100 and $300 per month, and came with features that let anyone vibe code a customized attack.
The takedown
The EvilTokens investigation came in the course of an ongoing partnership between security teams at Coinbase and Microsoft, which regularly swap intelligence on cyber threats. The companies spent months uncovering who was behind the Telegram campaign, and then shared their findings with law enforcement.
The investigation culminated in the Metropolitan Police nabbing the masterminds behind the EvilTokens scam on September 11. In a statement, the unit said two men, aged 32 and 38, were arrested on suspicion of making articles for use in fraud and money laundering offenses, and that they have been released on bail as the investigation continues.
In the course of mapping the phishing activity, investigators determined the perpetrators of the scam had collected around $1.1 million between October 2025 and June 2026. The money was paid in cryptocurrency to wallets on the Tron blockchain, and came from over 700 distinct addresses.
In a separate element of the investigation, Microsoft filed civil lawsuits that resulted in the seizure of 50 websites and the disabling of more than 175 domains tied to EvilTokens’ infrastructure. Upon seizing the domains, Microsoft posted the following splash page to publicize the takedown:

While the EvilTokens investigation began as a collaboration between Microsoft and Coinbase, it the anti-phishing campaign evolved into a broader coalition of firms, including Cloudflare and OpenAI.
According to Coinbase, at the time of the takedown, the EvilTokens perpetrators were working on newer phishing tools to target Okta and Gmail accounts.
investment News
Coinbase,Cryptocurrency,Hacking,Microsoft
