Finance.Yahoo Microsoft Disrupts AI-Driven Phishing Service EvilTokens
Article Content
- •EvilTokens compromised over 12,000 email accounts across 10,000 organizations.
- •Microsoft's operation seized 50 websites and disabled 150 domains linked to the cybercrime service.
- •The attack leveraged AI to identify targets for phishing and fraud.
Microsoft has disrupted the EvilTokens cybercrime service through a court-authorized operation in collaboration with law enforcement and industry partners. The operation resulted in the seizure of 50 websites and the disabling of over 150 related domains. EvilTokens had compromised more than 12,000 email inboxes across 10,000 organizations, utilizing AI to identify payment conversations and potential impersonation targets. The attack method involved sifting through stolen emails to facilitate fraud attempts. Microsoft shares remained flat at $497.64 as of September 23, 2026, 15.2% below its estimated fair value. The operation aims to enhance account protection for Microsoft 365 users, with a focus on preventing future compromises. The current status indicates that while infrastructure has been removed, the challenge remains in preventing future attacks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Microsoft in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Microsoft and Partners Disrupt EvilTokens AI-Powered Phishing Service Microsoft, in collaboration with various partners, has successfully disrupted EvilTokens, a phishing-as-a-service platform that compromised over 12,000 Microsoft 365 accounts across more than 10,000 organizations globally. The platform exploited the OAuth 2.0 device code authentication flow, allowing attackers to…
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…