Microsoft Disrupts AI-Powered EvilTokens Phishing Service Linked to 12,000 Compromised Inboxes
Microsoft's Digital Crimes Unit has disrupted EvilTokens, an AI-powered phishing-as-a-service platform linked to the compromise of over 12,000 email inboxes across more than 10,000 organisations worldwide since February 2026.
The coordinated operation resulted in the seizure of 50 websites used to operate EvilTokens and the disabling of more than 150 additional domains supporting the service.
The platform allowed attackers to generate device codes and trick victims into entering them on Microsoft's legitimate sign-in page, providing mailbox access without revealing the victim's password.