Microsoft dismantles EvilTokens phishing platform
Microsoft’s Digital Crimes Unit announced on September 22 that it had taken down EvilTokens, a phishing‑as‑a‑service operation that compromised more than 12,000 Microsoft 365 inboxes across over 10,000 organizations worldwide. The service, tracked internally as Storm‑2992, offered subscription tiers priced between $600 and $1,500 and included AI‑generated phishing lures and automated tools to…
Key points
- Microsoft DCU shut down EvilTokens, which had compromised >12,000 Microsoft 365 inboxes across 10,000+ organizations.
- The service sold AI‑generated phishing lures for $600‑$1,500 and used the device‑code OAuth flow to bypass MFA.
- Two UK administrators (32 and 38) were arrested; investigations involve SpyCloud, Health‑ISAC and local law enforcement.
EvilTokens exploited Microsoft’s device‑authorization grant flow, a legitimate OAuth process, to issue real device codes that gave attackers persistent tokens and bypassed MFA. SpyCloud’s analysis recorded 8,708 compromised accounts spanning 6,585 domains in 79 countries, while Huntress telemetry showed a 1,380% rise in device‑code phishing attacks after the platform appeared in February 2026. Two UK administrators, aged 32 and 38, were arrested in coordination with Health‑ISAC, SpyCloud and local law enforcement, though they remain on bail pending further investigation.
The takedown underscores the collaborative effort needed to combat AI‑enhanced cybercrime and highlights Microsoft’s recent conditional‑access policies aimed at restricting the vulnerable device‑code flow.
Microsoft dismantles AI-powered phishing platform EvilTokens
cryptobriefing.com · 22 September 2026
Loading the full article…
This text was published by cryptobriefing.com and written by Editorial Team. It is reproduced here with attribution so you can read it in full; the rights remain with the publisher. Read it at the source ↗
The headline, key points and digest above were generated by Digest AI's editorial model from the linked sources. Automated summaries can contain errors: the sources are the record. Spotted a mistake? Tell us. Published by Martin K., who runs Digest AI and handles corrections.
More in Society & Work
All →- Shopify CEO calls AI‑generated unchecked work “slop grenades” · 2 src
- Opinion: AI hallucinations would get employees fired, author argues · 1 src
- Google AI Mode suggests uninstalling driver, worsening laptop display issue · 1 src
- Stanford R&DE used AI to alter students' race and gender in ads · 1 src
- Opinion: starting ChatGPT after 40 reveals common beginner hurdles · 1 src
Comments
via GitHub Discussions