Coinbase
Microsoft, Coinbase, and law enforcement dismantle EvilTokens cybercrime network
Blockchain tracing helped expose $1.1 million in illicit revenue flowing through Tron addresses as authorities arrested two suspects in the UK
A joint operation between Microsoft, Coinbase, and law enforcement agencies has taken down EvilTokens, an AI-powered phishing-as-a-service platform that compromised over 12,000 email inboxes across more than 10,000 organizations in 79 countries. Two alleged operators were arrested in London on September 11, 2026.
Coinbase’s contribution was tracing approximately $1.1M in illicit revenue across four Tron addresses and more than 700 distinct deposit addresses linked to the operation.
What EvilTokens actually did
EvilTokens launched in February 2026 and operated as a subscription service for cybercriminals. The platform charged a $1,500 setup fee and $500 per month.
The platform’s specialty was device-code attacks, a technique that tricks users into authenticating on a legitimate Microsoft login page while secretly handing their session tokens to attackers. This method effectively bypasses multi-factor authentication.
EvilTokens didn’t stop at credential theft. The platform featured an AI chatbot specifically designed for inbox analysis and fraud planning. Once inside a compromised account, operators could use the chatbot to scan emails for financial information, identify high-value targets within an organization, and plan follow-up attacks. About 1,000 cybercriminals reportedly used the service, and Microsoft tracks the threat actor behind it as Storm-2992.
Marketing happened through Telegram channels.
The news moving money, markets, and the world—before your day starts.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
How Coinbase and Microsoft coordinated the takedown
The operation moved forward under a US District Court order that authorized Microsoft and its partners to seize 50 websites and disable more than 150 domains associated with EvilTokens.
Coinbase’s blockchain analysis team provided the financial forensics. By tracing transactions across four Tron addresses, investigators mapped out approximately $1.1M in revenue generated by EvilTokens operators. The trail extended across more than 700 distinct deposit addresses.
On September 11, 2026, the UK Metropolitan Police arrested two individuals connected to the operation, aged 32 and 38. Both were later released on bail.
The geographic footprint of the attacks was concentrated in the US, Canada, the UK, Australia, India, and France. The breadth of the campaign spanned 79 countries total.
A pattern of public-private takedowns
In March 2026, a similar public-private collaboration took down the Tycoon 2FA phishing service, which used comparable techniques to bypass multi-factor authentication on Microsoft accounts.
The $1.1M in traced revenue likely represents only the directly attributable funds flowing through identified addresses. With roughly 1,000 cybercriminals having used the service and 12,000 inboxes compromised, EvilTokens generated roughly $1,100 per customer in traceable revenue while charging $1,500 upfront plus $500 monthly.