EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts
Microsoft and partners seized 50 websites and disabled more than 150 domains tied to the AI-enabled phishing service, which also drew about 1,000 cybercriminal users.
- On Tuesday, Microsoft and industry partners disrupted EvilTokens, an AI-enabled phishing service linked to 12,000 compromised email inboxes across more than 10,000 organizations globally.
- EvilTokens utilized an AI-style chatbot to analyze victims' inboxes and identify sensitive details, allowing cybercriminals to bypass multi-factor authentication to silently authenticate as victims.
- Late last week, Microsoft seized 50 websites used to operate the service, while London's Metropolitan Police Service arrested two men, aged 32 and 38, who allegedly acted as administrators.
- Coinbase traced about $1.1 million in revenue for EvilTokens from paying customers, while Microsoft correlated at least 13 complaints representing approximately $1.7 million in reported losses.
- Experts advise organizations to treat unsolicited device codes as a red flag, assuming that once an inbox is compromised, criminals may understand its contents in minutes, not days.
11 Articles
11 Articles
Microsoft and UK Police Dismantle EvilTokens Phishing Service That Compromised 12,000 Accounts
UK police arrested two suspected administrators of EvilTokens, a phishing service that compromised over 12,000 Microsoft 365 accounts at more than 10,000 organizations. Microsoft seized 50 sites and disabled 150+ domains in a multi-partner operation that highlighted the platform's AI-driven sophistication and device-code MFA bypass.
Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud
The popular phishing-as-a-service platform used AI throughout the attack chain, allowing cybercriminals to steal tokens for account takeover and business email compromise.
UK cops arrest 2 EvilTokens suspects, Microsoft seizes 50 phishing kit websites
Used by crims to compromise 12K+ email inboxes across 10K+ global orgs
EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts
The EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft's Digital Crimes Unit (DCU).
Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every step of the attack chain." The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved the efforts of Health-ISAC, alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud,
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium









