Tools
Microsoft disrupted EvilTokens AI PhaaS tied to ~12K mailboxes
Microsoft’s Digital Crimes Unit says it disrupted EvilTokens — a PhaaS platform whose AI chatbot analyzed stolen inboxes and steered financial fraud — after links to more than 12,000 mailboxes across over 10,000 organizations; BleepingComputer tracks the actor as Storm-2992, and UK police arrested two suspects. Unlike legitimate support chatbots such as Chatbase trained on an organization’s own docs, this was a criminal subscription chatbot sold for fraud prep. High-level only per Microsoft’s blog and BC: no phishing recipes, no malware steps. This is Microsoft’s EvilTokens / Storm-2992 disruption, not Gambit’s skimmer campaign, not the OpenAI Medicare agent case, and not Cursor.