/Submit incident
Documented

Microsoft and Partners Dismantle AI-Powered EvilTokens Phishing Platform

September 22, 2026
oecd:2026-09-22-c7a8View source ↗

What happened

Microsoft, Coinbase, and law enforcement dismantled EvilTokens, an AI-driven phishing service that compromised 12,000 Microsoft accounts across 10,000 organizations. The platform used AI chatbots to analyze inboxes, identify targets, and automate fraud, leading to financial harm. Two suspects were arrested in the UK, and $1.1 million in illicit revenue was traced.

Reported impact

Affected parties
Not publicly disclosed
Harm type
Not publicly disclosed
Scale
Not publicly disclosed
Financial impact
Not publicly disclosed
Regulatory action
Not publicly disclosed

Classification

Organization
Not publicly disclosed
AI system
Not publicly disclosed
Industry
Not publicly disclosed
Country
Not publicly disclosed
Provider
Not publicly disclosed
Incident type
Not publicly disclosed

Relevant governance controls

Governance control mapping is not available for this record.

  • No controls mappedNot publicly disclosed

Control mapping is analytical. It does not state that any control would have prevented the incident.

Sources and evidence

OECD AI Incidents Monitor
Primary source
Microsoft and Partners Dismantle AI-Powered EvilTokens Phishing Platform
2026-09-22