Circuit Wire — a daily news update from the Circuit.

Microsoft's Digital Crimes Unit announced on Tuesday that it had disrupted EvilTokens, a phishing service linked to more than 12,000 compromised email inboxes at over 10,000 organizations, and that London's Metropolitan Police had arrested two men suspected of running it, The Record reported.

Officers executed warrants on Friday at addresses in Canary Wharf and Nine Elms, according to BleepingComputer. The men, aged 32 and 38, were arrested on suspicion of making articles for use in fraud and money laundering offenses. Both have been released on bail while the investigation continues. Microsoft first reported the pair to the Met in August.

EvilTokens launched in February 2026 and sold access through Telegram for a $1,500 initiation fee plus $500 a month. Microsoft tracks its operator as Storm-2992. The service specialized in device-code phishing, which abuses a legitimate Microsoft sign-in process built for smart TVs, printers and conferencing equipment. Victims are tricked into entering a code that authorizes the attacker's session, giving access to their account without a password and despite multifactor authentication.

Once inside an account, the platform used AI tools to work through the inbox. It could summarize and translate emails, find wire-transfer discussions and pending invoices, map who handled payments, and draft messages impersonating trusted contacts for business email compromise fraud. Microsoft said work that once took criminals days or weeks was largely automated within minutes. "AI was not simply helping attackers write more convincing messages," said Steven Masada, associate general counsel in the Digital Crimes Unit.

Microsoft said targeted organizations were concentrated in the US, Canada, the UK, Australia, India and France. Affected sectors included wholesale distribution, construction, financial services, real estate, higher education and healthcare.

The company partnered with the health sector nonprofit Health-ISAC on a lawsuit in US District Court that authorized it to seize the platform's infrastructure. Microsoft and its partners seized 50 websites used to run the service and disabled 150 more domains. The action is the unit's 40th court-authorized disruption and its first against what Microsoft called an end-to-end AI-enabled cybercrime service. Earlier targets included the RaccoonO365 and RedVDS platforms.

BleepingComputer noted that the operation was a disruption rather than a full takedown, and that the threat remains active at lower volume. Affiliates have already built copycat kits, and at least 10 phishing platforms supported the device-code technique by April.

Want a weekly roundup of the major stories shaping the security industry? The On The Circuit newsletter is read by more than 12,000 protection professionals.

Spotted something we should cover? Send tips and feedback via circuit-magazine.com.