\n\n\n\n Phishing Got a Chatbot Sidekick and Microsoft Pulled the Plug - Agent 101 \n

Phishing Got a Chatbot Sidekick and Microsoft Pulled the Plug

📖 5 min read•813 words•Updated Sep 24, 2026

The scariest thing about EvilTokens was not the AI, it was the subscription button.

On 22 September 2026, Microsoft announced that its Digital Crimes Unit, working with industry partners and law enforcement, had disrupted EvilTokens, an AI-assisted phishing-as-a-service platform. The numbers Microsoft reported: more than 12,000 compromised inboxes across over 10,000 organizations. The Metropolitan Police Service arrested two men, aged 32 and 38, on 11 September 2026 in connection with the operation.

If you follow AI news mostly through headlines, this one probably registered as “hackers used AI, again.” I want to slow it down, because the structure of this thing tells you more about where AI agents are heading than any product launch this month.

Cybercrime with a pricing page

Microsoft described EvilTokens as a subscription-based service. That word choice matters. A subscription implies customers, onboarding, support, and someone maintaining the product so it keeps working. It means the people running it were not necessarily the people using it.

This is the same shift that happened in legitimate software over the past two decades. You used to need a server room to run a business application. Now you need a credit card. Criminal tooling has followed the same curve, and EvilTokens is a clean example of it: the technical skill got packaged up so the buyer did not need any.

Which means the relevant question is not “how sophisticated were the attackers?” It’s “how many people could suddenly do something they previously couldn’t?” Twelve thousand inboxes across ten thousand organizations suggests the answer was: quite a lot, spread quite thin.

Where the AI actually sat

Here is the part I find genuinely instructive for anyone trying to understand AI agents. Reporting on the takedown describes an AI chatbot inside the platform that helped attackers decide which victims to pursue and how to exploit them.

Notice what that is and is not. The AI was not the hacking tool. The phishing mechanism itself, which Microsoft identified as device-code phishing, is a known technique that does not require AI at all. The AI was sitting one layer above, doing judgment work: triage, prioritization, strategy.

That is what an agent-shaped system tends to be good at. Not replacing the tool, but replacing the human decision-making that connects tools to targets. Looking at a list, working out which items are worth the effort, and suggesting the next move.

When people ask me what AI agents are actually for, this is the least comfortable but clearest answer I can give. They are for the part of the job that used to require experience. The part where someone had to look at a pile of stolen access and know which pieces were valuable.

Strip the criminality out and you have described half the enterprise AI pitches currently in circulation. Same shape. Different intent.

Why the arrests are the headline

A lot of AI safety conversation focuses on the models themselves, as though the only lever is what the software will or won’t do when asked. This takedown worked differently. Microsoft’s Digital Crimes Unit coordinated with industry partners and authorities, infrastructure came down, and two suspected administrators were arrested by police.

That is old-fashioned enforcement applied to a new-fashioned product. The AI component did not make the operators harder to find. They were running a business, and businesses leave traces: payments, hosting, customers, communications.

I think that is a useful corrective to the fatalism you sometimes hear, the idea that AI-assisted crime is inherently unstoppable because the tools are cheap and widely available. The tools may be cheap. The operation around them still has to exist somewhere, run by someone.

What this means if you are not in security

A few practical takeaways, kept plain:

  • Volume is the change, not cleverness. AI lowers the cost of attempting an attack, so expect more attempts rather than fundamentally stranger ones.
  • The attack was against accounts, not software. More than 12,000 inboxes were compromised. Inboxes are the front door to nearly everything else you own online.
  • Phishing targeting has gotten more selective. If an AI is helping decide who to pursue and how, generic “you would never fall for it” confidence is a weaker defense than it used to be.
  • Small organizations were in scope. Ten thousand-plus organizations affected means this was not limited to large, obvious targets.

The pattern worth watching

EvilTokens is gone, and two people are facing consequences. The interesting residue is the blueprint: take a known technique, wrap it in a service, drop an AI layer on top to handle the thinking, and sell access.

That blueprint is not specific to crime, which is exactly why it will keep showing up. The same architecture that made this platform effective is the architecture behind the agent products being built for legitimate work right now. Understanding one helps you read the other, and reading both is going to be part of basic digital literacy sooner than most people expect.

🕒 Published:

🎓
Written by Jake Chen

AI educator passionate about making complex agent technology accessible. Created online courses reaching 10,000+ students.

Learn more →
Browse Topics: Beginner Guides | Explainers | Guides | Opinion | Safety & Ethics
Scroll to Top