$1,500 signup fee, $500 a month, and an AI analyst that reads a hacked inbox to figure out exactly which employee controls the money. That's the actual product EvilTokens was selling, not a phishing kit with AI bolted on, the AI was the business model itself.

This is Microsoft DCU's 40th court-authorized disruption in nearly two decades, but the first specifically against an end-to-end AI-enabled cybercrime service, a real distinction, not just a bigger case number. EvilTokens launched in February 2026 and compromised over 12,000 inboxes across more than 10,000 organizations, hitting wholesale distribution, construction, financial services, real estate, healthcare, and higher education across the US, UK, Canada, Australia, India, and France. It abused Microsoft's OAuth 2.0 device code login flow to steal session tokens directly, bypassing passwords and MFA entirely.

Coinbase's role was tracing the money. Its threat team traced roughly $1.1 million in revenue across four Tron addresses between October 2025 and June 2026, over 1,000 deposits from more than 700 distinct sources. That trail fed the federal court order, 50 websites seized, more than 175 domains disabled. Two men, 32 and 38, were arrested by London's Met Police on September 11, released on bail pending forensic examination.

What stands out to me is the coalition size, Cloudflare, OpenAI, TRM Labs, Health-ISAC, Shadowserver, SpyCloud and Railway all contributed alongside Microsoft and Coinbase. A genuinely broad response to a threat model that's now public knowledge and easy to copy.

What I'm watching: whether similar AI-driven, device-code-exploiting services start appearing now that EvilTokens proved the model works, and how fast platforms tighten device code flow defenses in response.
$BTC #BTC Price Analysis# #Meme Alpha# #BNBChain# $COIN