Microsoft successfully dismantled EvilTokens, an AI-powered chatbot designed to aid cybercriminals in automating fraud and hacking operations. Leveraging court orders, Microsoft forced the platform offline and worked closely with law enforcement in the United Kingdom to apprehend two individuals connected to the service.
EvilTokens was marketed as an AI assistant for cybercrime, assisting users with phishing, social engineering, and other illicit hacking tasks. Its sophisticated interface enabled even novice criminals to carry out complex attacks by automating steps previously requiring expert knowledge.
The tech giant’s intervention represents a significant move in tackling the use of artificial intelligence in cybercrime. Microsoft employed legal mechanisms to seize control of EvilTokens’ infrastructure and remove it from public use, setting a precedent for countering AI-enhanced criminal tools.
Authorities in the UK, in cooperation with Microsoft, used the intelligence gathered from the takedown to identify and arrest two suspects believed to operate or benefit from EvilTokens. The arrests mark a coordinated effort between private tech firms and law enforcement to disrupt emerging cyber threats quickly.
The EvilTokens platform exemplified a broader trend where criminals increasingly deploy AI to lower the technical barrier and scale fraud operations. By offering AI-driven answers and suggestions tailored to cybercrime tactics, such tools pose new challenges for cybersecurity defenders.
This case underscores the evolving landscape of cyber threats spurred by AI technologies, highlighting the necessity of legal action and partnerships between corporations and government agencies to counteract criminal innovation efficiently. Microsoft has reaffirmed its commitment to combating malicious AI applications and supporting international law enforcement efforts.

