Microsoft Disrupts EvilTokens Phishing Service That Hit 12,000 Accounts
A court-authorized operation dismantled an AI-powered phishing platform and led to two arrests in the UK.
Microsoft's Digital Crimes Unit, acting with court authorization, disrupted EvilTokens, a phishing-as-a-service platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations. The operation also resulted in the arrest of two suspects in the UK, according to all four sources.
The sources agree on the scale of the compromise and the takedown, but they differ in emphasis. The Hacker News reports that Microsoft said the service used AI throughout the attack chain, while Recorded Future News notes that EvilTokens was sold on Telegram for a $1,500 initiation fee and a $500 monthly subscription. BleepingComputer describes the platform as PhaaS, and The Register adds that 50 phishing kit websites were seized.
The arrests and website seizures suggest the operation targeted both the operators and the infrastructure. The service was designed to help cybercriminals compromise accounts, analyze breached inboxes, and identify ways to monetize access, according to Recorded Future News.
Sources · 8
- Windows CLOSEDQUORUM malware uses AI models to autonomously select post-compromise actions
- Microsoft Disrupts EvilTokens Device Code Phishing Service
- Microsoft disrupts AI-assisted platform that compromised 12,000 accounts
- New ClosedQuorum Windows malware uses AI for attack decisions
- Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
- Two arrested in UK after Microsoft takedown of ‘Eviltokens’ AI-chatbot for cybercriminals
- UK cops arrest 2 EvilTokens suspects, Microsoft seizes 50 phishing kit websites
- EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts
More in Security & Privacy
Canada Probes IDScan After Breach of 153M Driver's Licenses
Privacy Commissioner opens investigation into IDScan.net's security practices and breach notifications after stolen ID scans of 153 million people appeared on the dark web.
AI Relay Servers Mask Chinese Access to US Frontier Models
More than 80,000 AI relay servers are helping users in China hide their identities while accessing cutting-edge US AI models, likely to clone them.
Sweden Fines Miljödata $183,000 for Breach Affecting 2.2 Million
Sweden's privacy regulator penalized IT provider Miljödata for security failures linked to a breach that exposed 2.2 million people's data.
Rogue External MFA Providers Can Steal Passwords in Login Attacks
Researchers show that attackers with privileged access can register a malicious external MFA provider that harvests passwords during otherwise legitimate logins.