Skip to content

Microsoft disrupts AI-powered phishing tool but censors criticism poorly

Microsoft scored a win in cybersecurity by dismantling EvilTokens, an AI-powered phishing platform responsible for compromising thousands of inboxes. However, the company also faced backlash for attempting to censor criticism of its AI integrations, underscoring the challenges of balancing security and public perception.

Editor, Lazyfounder

Published Updated 6 min read

Microsoft scored a win in cybersecurity by dismantling EvilTokens, an AI-powered phishing platform responsible for compromising thousands of inboxes. However, the company also faced backlash for attempting to censor criticism of its AI integrations, underscoring the challenges of balancing security and public perception.

30 SEC SUMMARY

  • Microsoft and partners disrupted EvilTokens, an AI-powered phishing-as-a-service platform, leading to two arrests and the seizure of 200+ domains.
  • EvilTokens compromised 12,000 inboxes across 10,000 organizations, primarily in the US, using AI to scale attacks.
  • A Windows 11 September update broke the File History backup feature, which Microsoft later addressed with an optional patch.
  • Microsoft briefly blocked the term 'Microslop' on its Copilot Discord channel, sparking criticism and comparisons to the Streisand effect.

TABLE OF CONTENTS

  • Microsoft disrupts AI-powered phishing platform
  • Windows 11 update breaks backup feature
  • Microsoft’s ‘Microslop’ censorship backfires
  • Broader context on cybercrime and AI
  • What this means
  • Key takeaways
  • FAQ
  • Sources

KEY HIGHLIGHTS

  • Microsoft, UK police, and partners disrupted EvilTokens, a phishing-as-a-service platform, leading to two arrests and the seizure of over 200 domains.
  • EvilTokens used AI to compromise 12,000 inboxes across 10,000 organizations, primarily in the US.
  • A Windows 11 update broke the File History backup feature, which Microsoft later fixed with an optional patch.
  • Microsoft briefly blocked the term ‘Microslop’ on its Copilot Discord channel, sparking backlash and comparisons to the Streisand effect.

Microsoft disrupts AI-powered phishing platform

Microsoft, in collaboration with the UK Metropolitan Police Service and partners like Cloudflare, Health-ISAC, and OpenAI, disrupted EvilTokens, a phishing-as-a-service (PhaaS) platform that used AI to scale cyberattacks. According to TechRadar, the operation led to the arrest of two suspects, aged 32 and 38, who were later released on bail.

The takedown resulted in the seizure or disabling of over 200 domains associated with EvilTokens. The platform, sold via Telegram for $1,500 with a $500 recurring subscription, targeted high-value victims across industries such as wholesale distribution, construction, financial services, real estate, higher education, and healthcare.

EvilTokens compromised more than 12,000 inboxes across 10,000 organizations globally, with the majority of victims located in the US. The platform’s AI-driven approach contributed to a 1,380% increase in device-code phishing attacks in 2026 compared to the same period in 2025.

Windows 11 update breaks backup feature

A September 2026 Windows 11 update (KB5124008) introduced a bug that broke the File History backup feature, preventing users from creating or updating backups to external drives or network locations. According to TechRadar, Microsoft acknowledged the issue and released an optional patch to address it.

While the fix restored basic functionality, some users reported lingering issues with the ‘Run now’ feature and synchronization delays. The ‘Run now’ glitch dates back to a July 2026 update, highlighting persistent stability problems in Windows 11 throughout the year.

TechRadar advised users to wait for the official October 2026 update for a more stable resolution, as minor bugs may still persist in the optional patch.

Microsoft’s ‘Microslop’ censorship backfires

Microsoft briefly blocked the term ‘Microslop’ on its Copilot Discord channel, citing it as a ‘temporary anti-spam measure.’ The term originated from a comment by Microsoft’s CEO about ‘AI slop,’ a phrase used to critique the company’s forced AI integrations in Windows 11.

The censorship sparked backlash, with critics accusing Microsoft of attempting to suppress criticism. According to TechRadar, the move had the opposite effect, amplifying negative sentiment under the Streisand effect, where efforts to hide or censor information draw more attention to it.

Microsoft later reversed the block, and mentions of ‘Microslop’ have since decreased on platforms like Reddit and X. However, the term is expected to remain associated with Microsoft indefinitely, serving as a reminder of the controversy.

Broader context on cybercrime and AI

Phishing-as-a-service platforms like EvilTokens reflect a growing trend of cybercriminals leveraging AI to automate and scale attacks. These tools lower the barrier to entry for malicious actors, enabling even inexperienced hackers to target organizations with sophisticated phishing campaigns.

The rise of device-code phishing, a method exploited by EvilTokens, highlights the need for organizations to adopt stricter authentication protocols. Device-code attacks bypass traditional security measures by tricking users into granting access to cloud services, making them particularly difficult to detect.

What this means

LazyFounders analysis — our interpretation, not reported fact.

For founders and operators, this story highlights two critical themes: cybersecurity risks in an AI-driven landscape and the reputational pitfalls of overzealous moderation.

The takedown of EvilTokens shows how quickly malicious actors can weaponize AI to scale phishing attacks, targeting thousands of organizations with minimal effort. For startups, this underscores the importance of investing in robust security measures—especially if your team or customers rely on cloud-based or enterprise tools. The fact that EvilTokens exploited device-code phishing, a method that surged by 1,380% in 2026, signals that attackers are becoming more sophisticated. Founders should prioritize employee training, multi-factor authentication, and regular security audits to mitigate such risks.

On the flip side, Microsoft’s handling of the ‘Microslop’ controversy serves as a cautionary tale. Attempting to suppress criticism—even for something as trivial as a nickname—can backfire spectacularly, amplifying negative sentiment instead of quelling it. For startups, this is a reminder that transparency and humility go a long way in maintaining trust. Whether it’s a buggy update or an unpopular feature, addressing issues head-on (and with a sense of humor, if appropriate) is often the better strategy than censorship.

Key takeaways

  • EvilTokens, an AI-powered phishing tool, was disrupted by Microsoft and partners, leading to two arrests and the seizure of 200+ domains.
  • The platform compromised 12,000 inboxes across 10,000 organizations, primarily in the US, using AI to target high-value victims.
  • Windows 11’s September update broke the File History backup feature, which Microsoft later fixed with an optional patch, though minor issues persist.
  • Microsoft briefly blocked the term ‘Microslop’ on its Copilot Discord channel, sparking backlash and comparisons to the Streisand effect.
  • Criticism of Microsoft’s AI integrations has decreased as the company addressed bugs and reduced forced AI features in Windows 11.

FAQ

What was EvilTokens, and how did it operate?

EvilTokens was a phishing-as-a-service (PhaaS) platform that used AI to automate and scale phishing attacks. Sold via Telegram for $1,500 with a $500 recurring subscription, it targeted high-value victims across industries like financial services, healthcare, and education. The platform compromised over 12,000 inboxes across 10,000 organizations, primarily in the US.

How did Microsoft fix the Windows 11 File History bug?

Microsoft released an optional patch (KB5124008) to address the File History bug introduced in the September 2026 update. While the fix restored basic functionality, some users reported lingering issues with the ‘Run now’ feature and synchronization delays. A more stable fix is expected in the October 2026 update.

Why did Microsoft block the term ‘Microslop’ on Discord?

Microsoft blocked the term ‘Microslop’ on its Copilot Discord channel as a ‘temporary anti-spam measure.’ The term originated from criticism of the company’s forced AI integrations in Windows 11, particularly a comment by Microsoft’s CEO about ‘AI slop.’ The censorship sparked backlash and was later reversed.

Related on LazyFounders

Sources

  1. TechRadar · 2026-09-23
    Microsoft takes down AI-boosted phishing tool that hit 12,000 accounts
  2. TechRadar · 2026-09-24
    Microsoft admits it broke Windows 11 backup feature in September update — here's how to fix it (but you might want to hold off)
  3. TechRadar · 2026-09-24
    Microsoft is trying to forget 'Microslop' now rather than censor the word — but I think it's a term that'll hang around the firm's neck for the rest of time

This story is an original summary drafted with AI by Lazyfounder from the reporting listed above and checked by automated validation. Facts are attributed to their original publishers; sections marked as analysis are Lazyfounder's. Where a source is in another language, facts were machine-translated and quotations are reported, not reproduced. Read the original coverage via the links, and see our AI policy and corrections policy.

About the author

Editor, Lazyfounder

Tarun Mottlia edits LazyFounders, covering Indian startups, funding rounds, AI and product launches. Every story on the site is AI-assisted and checked against its cited sources before publication.

More stories by Tarun Mottlia

Get the LazyFounder Brief

Startup, funding and AI news in a five-minute read. Join the early-access list.

Lazy Founder - Powered by Blogy.in

Contact us

Have a story tip, correction or partnership idea?

Write to us at tarun.kumar@blogy.in or message us on WhatsApp. We read every message.