#5
The Hacker News
general
September 22, 2026 at 17:03 UTC
Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
By [email protected] (The Hacker News)
AI Summary
Microsoft, acting under a U.S. District Court for the Eastern District of Virginia authorization, seized 50 websites and disabled 150+ domains belonging to EvilTokens, an AI-powered phishing-as-a-service platform linked to 12,000 Microsoft 365 inbox compromises. EvilTokens used AI throughout the attack chain — for crafting social engineering lures, selecting targets, and conducting device code phishing. The takedown involved Health-ISAC, Cloudflare, Coinbase, OpenAI, and SpyCloud.
Relevance score: 86.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →