Home / Sep 24, 2026 / Story
0
#5 The Hacker News general September 22, 2026 at 17:03 UTC

Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises

By [email protected] (The Hacker News)

AI Summary

Microsoft, acting under a U.S. District Court for the Eastern District of Virginia authorization, seized 50 websites and disabled 150+ domains belonging to EvilTokens, an AI-powered phishing-as-a-service platform linked to 12,000 Microsoft 365 inbox compromises. EvilTokens used AI throughout the attack chain — for crafting social engineering lures, selecting targets, and conducting device code phishing. The takedown involved Health-ISAC, Cloudflare, Coinbase, OpenAI, and SpyCloud.

Relevance score: 86.0/100

# More from September 24