Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises

Cybersecurity · September 23, 2026

Cybersecurity·thehackernews.com

Microsoft's Digital Crimes Unit won a court-authorized takedown of EvilTokens, a device-code phishing platform blamed for compromising more than 12,000 inboxes across upwards of 10,000 organizations. Microsoft says the operation leaned on AI throughout its attack chain, and the disruption effort drew in partners including Health-ISAC, Cloudflare, Coinbase, OpenAI, and Shadowserver. The action was authorized by a federal court in the Eastern District of Virginia.

// source: thehackernews.com ↗

Back to Blog