Original Geeknewz analysis of Microsoft Digital Crimes Unit and Cloudflare Cloudforce One primary reports on EvilTokens (Storm-2992). Numbers below come from those disclosures; the break-even framing is ours.
Most AI crime stories sound like sci-fi. EvilTokens sounded like a pricing page. For a $1,500 initiation fee and $500 a month, Telegram buyers got a phishing-as-a-service panel that stole Microsoft 365 session tokens, then handed criminals an AI coach that read the victim’s inbox and suggested who to impersonate next. Microsoft says the kit, tracked as Storm-2992, helped compromise more than 12,000 inboxes across over 10,000 organizations after launching in February 2026. This week’s coordinated disruption, with Cloudflare yanking Workers infrastructure and UK police arresting two men, is the part you already saw in headlines. The part worth sitting with is how cheaply that scale was sold.

What $2,000 actually bought
Microsoft’s Digital Crimes Unit and Threat Intelligence blogs spell out the product shape clearly. Device-code phishing abused a real Microsoft sign-in flow meant for TVs and conference gear. Victims typed a code on microsoft.com/devicelogin and authorized the attacker’s session without handing over a password. Once inside, EvilTokens’ AI tools summarized mail, mapped “money movers,” surfaced wire-transfer threads, and drafted follow-ups that looked like they came from a trusted coworker. Cloudflare separately documented how customers could paste their own Cloudflare API keys so the panel could spin Workers that collected credentials and hosted lure pages.
That is not “AI wrote a scarier email.” It is AI collapsing the slow, expert part of business email compromise into a dashboard. Traditional BEC required someone who could read an org chart out of a messy inbox. EvilTokens rented that skill by the month.

Attacker cost table (Geeknewz math)
Using Microsoft’s published list prices alone, here is what a six-month run looked like on paper. Extra Essential Tools (Antibot, SMTP sender, and so on) cost more; we leave those out so the floor stays honest.
| Scenario | Upfront | Monthly | 6-month total | Notes |
|---|---|---|---|---|
| Single affiliate, base kit | $1,500 | $500 | $4,500 | $1,500 + (6 × $500) |
| Same kit, 3-month experiment | $1,500 | $500 | $3,000 | Cheap enough to try, expensive enough to feel “serious” |
| Implied cost if 12,000 inboxes were one shared pool | — | — | ~$0.38 per inbox | $4,500 ÷ 12,000 (illustrative only; many buyers shared the victim set) |
That last row is deliberately blunt. Microsoft does not say one customer owned all 12,000 compromises, and Cloudflare’s report shows a whole affiliate economy. Still, the ratio tells you why PhaaS keeps winning: even if ten buyers split the victim pool, each is paying SaaS money for enterprise-scale damage. A single successful wire redirect pays for years of subscriptions.
How we got here (short timeline)
January–February 2026: EvilTokens appears on Telegram and starts selling the panel. April 2026: Microsoft tracks campaigns spinning thousands of short-lived polling nodes to generate device codes and dodge signatures. September 11, 2026: UK Metropolitan Police arrest two men linked to the alleged operation. Mid-September: Cloudflare and Microsoft execute the technical and civil takedown (50 sites seized, 150-plus domains disabled, Workers purged). September 22: Microsoft and Cloudflare publish the primary write-ups the rest of the industry is now quoting.
From first Telegram storefront to court-authorized disruption took roughly seven months. That is fast for law enforcement and partners. It is also long enough for thousands of organizations to learn, the hard way, that MFA alone does not stop token theft.
Geeknewz take
Treat EvilTokens as a pricing lesson, not a one-off villain. When inbox reconnaissance and impersonation drafts ship as a $500/month add-on, defenders should assume a stolen session becomes actionable in minutes. Block device-code flow where you do not need it, prefer phishing-resistant MFA (passkeys or FIDO), and verify any payment-change request on a second channel that is not email. The kit is down. The business model is not.
