#EvilTokens
-A network of 10,000 AI servers masks Chinese malicious activity
-Ukrainian hackers leak Russia's naval secrets
-ShinyHunters hack the FBI
-Tech firms disrupt EvilTokens PhaaS
-BigCommerce notifies merchants of security breach

P: risky.biz/RBNEWS614/
N: news.risky.biz/risky-bullet...
September 23, 2026 at 7:54 AM
Since emerging in February 2026, EvilTokens quickly became one of the most widely used phishing-as-a-service (PhaaS) platforms, enabling sophisticated device code phishing campaigns aimed at compromising organizational accounts at scale. msft.it/63321a54KS
Unmasking EvilTokens: Getting to the root of device code phishing | Microsoft Security Blog
EvilTokens has quickly become one of the top PhaaS platforms, enabling device code phishing attacks through AI-assisted lures, automated infrastructure, and token theft. In collaboration with partners, Microsoft Digital Crimes Unit (DCU) facilitated a disruption of EvilTokens infrastructure and operations.
msft.it
September 22, 2026 at 4:17 PM
AIが乗っ取ったメールを読み「どうすればできるだけ多くの金をだまし取れるか」まで教える犯罪サービス「EvilTokens」が展開されていた
https://gigazine.net/news/20260924-eviltokens/
AIが乗っ取ったメールを読み「どうすればできるだけ多くの金をだまし取れるか」まで教える犯罪サービス「EvilTokens」が展開されていた
AIに乗っ取ったメール受信箱を分析させて組織の人間関係や支払いの流れを調べ「誰を狙うべきか」「誰になりすますべきか」「どの関係を悪用すれば金銭詐欺が成功しやすいか」まで提案させるサイバー犯罪サービス「EvilTokens」が展開されていたことをMicrosoftが明らかにしました。
gigazine.net
September 24, 2026 at 3:46 AM
UK Cops arrest 2 EvilTokens suspects, Microsoft seizes 50 phishing kit websites
UK Cops arrest 2 EvilTokens suspects, Microsoft seizes 50 phishing kit websites
Used by crims to compromise 12K+ email inboxes across 10K+ global orgs
www.theregister.com
September 22, 2026 at 3:08 PM
The platform's approach represents a major shift in the mass compromise and post-compromise of accounts, which has been alarmingly expedited by AI.
Microsoft disrupts AI-assisted platform that compromised 12,000 accounts
EvilTokens provided an end-to-end platform that makes mass compromises faster and easier.
arstechnica.com
September 23, 2026 at 5:17 PM
The EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft's Digital Crimes Unit (DCU).
EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts
The EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft's Digital Crimes Unit (DCU).
www.bleepingcomputer.com
September 22, 2026 at 3:00 PM
Two arrested in UK after Microsoft takedown of ‘Eviltokens’ AI-chatbot for
cybercriminals
therecord.media/two-arrested...
Two arrested in UK after Microsoft takedown of ‘Eviltokens’ AI-chatbot for cybercriminals
Available on Telegram for a $1,500 initiation fee and a recurring monthly $500 subscription, EvilTokens provided cybercriminals with artificial intelligence tools enabling them to compromise accounts,...
therecord.media
September 23, 2026 at 10:53 AM
Microsoft’s EvilTokens takedown sheds light on state of AI-powered cybercrime www.csoonline.com/article/4225...
Microsoft’s EvilTokens takedown sheds light on state of AI-powered cybercrime
Surreptitiously gaining persistent access to compromised Microsoft 365/Entra ID accounts, the group also offered an AI-powered chatbot to facilitate BEC scams.
www.csoonline.com
September 26, 2026 at 2:42 AM
#Microsoft hat die Phishing-Plattform #EvilTokens zerschlagen. Der Dienst nutzte KI, um gestohlene Postfächer zu analysieren und gezielten Zahlungsbetrug vorzubereiten.
Microsoft zerschlägt gefährlichen KI-Chatbot und Datendieb EvilTokens
winfuture.de
September 22, 2026 at 5:00 PM
Microsoft Disrupts EvilTokens: How AI-Powered Device-Code Phishing Compromised 12,000+ Inboxes

CYBERSECURITY & PRIVACY · BREAKING ANALYSIS Microsoft Disrupts EvilTokens: How AI-Powered Device-Code Phishing Compromised 12,000+ Inboxes EvilTokens industrialized device-code phishing: victims could…
Microsoft Disrupts EvilTokens: How AI-Powered Device-Code Phishing Compromised 12,000+ Inboxes
CYBERSECURITY & PRIVACY · BREAKING ANALYSIS Microsoft Disrupts EvilTokens: How AI-Powered Device-Code Phishing Compromised 12,000+ Inboxes EvilTokens industrialized device-code phishing: victims could authenticate on a real Microsoft page yet still authorize an attacker session. Here is how it worked, what AI added, and the controls Microsoft 365 teams should prioritize. Published September 23, 2026 · Source-based security analysis · No independent forensics claimed…
digitalpulsebrief.com
September 23, 2026 at 2:20 AM
Microsoft Disrupts EvilTokens Device Code Phishing Service www.darkreading.com/identity-acc...
Microsoft Disrupts EvilTokens Device Code Phishing Service
Microsoft disrupted the EvilTokens phishing platform, which used AI-powered device code phishing to compromise thousands of organizations globally.
www.darkreading.com
September 25, 2026 at 12:12 PM
The cybercrime platform leveraged AI at every step of the attack chain, including writing social engineering messages and deciding targets. www.securityweek.com/ai-powered-p...
AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft
Microsoft and its partners have disrupted EvilTokens, a phishing platform that uses AI throughout the attack chain.
www.securityweek.com
September 23, 2026 at 12:31 PM
Coinbase & Microsoft take down EvilTokens, an AI phishing platform that used Telegram bots & exploited Microsoft's login process. They seized 50 websites & over 175 domains. The operation led to an arrest in the UK. EvilTokens reportedly made $1.1M.

#crypto #blockchain #news
September 22, 2026 at 4:01 PM
🖲️ #Noticia #CiberSeguridad #Cybersecurity #CiberNoticia

Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises

Leer Más / Read More...
Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
Haz clic para acceder al contenido completo.
thehackernews.com
September 22, 2026 at 5:44 PM
EvilTokens: la campaña de phishing obtiene accesos abusando de un mecanismo legítimo

#Ciberseguridad #Seguridad #Tecnología #LaiaDesk
EvilTokens: la campaña de phishing obtiene accesos abusando de un mecanismo legítimo
¿Qué sucede cuando un ataque utiliza infraestructura oficial en vez de falsificarla? EvilTokens marca una evolución en el phishing: ya no captura credenciales, sino que induce a la…
laiadesk.com
September 27, 2026 at 6:20 PM
This AI-powered cybercrime platform facilitated sophisticated business email compromise campaigns that compromised more than 12,000 inboxes in over 10,000 organizations worldwide. In collaboration with partners, Microsoft DCU facilitated a disruption of EvilTokens infrastructure. msft.it/6016a50CO
Disrupting EvilTokens: The AI Chatbot Built for Cybercrime - Microsoft On the Issues
Microsoft, Health-ISAC, industry partners and law enforcement coordinated legal and operational action to disrupt the EvilTokens cybercrime platform.
msft.it
September 22, 2026 at 4:19 PM
EvilTokens device-code phishing kit totally more evil than we all thought
EvilTokens device-code phishing kit totally more evil than we all thought
It's a 'complete BEC operations environment,' Talos researcher says
www.theregister.com
July 1, 2026 at 9:51 PM
AI-powered phishing kit busted, two arrested

Microsoft and law enforcement disrupted EvilTokens, an AI-powered phishing service that compromised 12,000 inboxes, with two alleged administrators arrested.

Looks like AI's utility for bad actors is only just beginning.
September 23, 2026 at 9:04 AM
A new malicious kit called EvilTokens integrates device code phishing capabilities, allowing attackers to hijack Microsoft accounts and provide advanced features for business email compromise attacks.
New EvilTokens service fuels Microsoft device code phishing attacks
A new malicious kit called EvilTokens integrates device code phishing capabilities, allowing attackers to hijack Microsoft accounts and provide advanced features for business email compromise attacks.
www.bleepingcomputer.com
April 1, 2026 at 7:42 PM
🚨 Coinbase and Microsoft disrupted EvilTokens, an AI-powered phishing network linked to 12,000+ compromised inboxes.

50 websites were seized, 150+ domains disabled, and two suspected operators arrested.

Coinbase also helped trace the crypto money trail.
September 24, 2026 at 2:12 AM