Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft Dismantles AI-Powered Phishing Network EvilTokens

Microsoft Dismantles AI-Powered Phishing Network EvilTokens

Posted on September 22, 2026 By CWS

Microsoft has dismantled the EvilTokens phishing service, a sophisticated operation leveraging artificial intelligence (AI) to orchestrate widespread email compromises. This takedown, announced on Tuesday, was executed with the aid of multiple partners, including Health-ISAC and Cloudflare. The initiative received legal backing from the U.S. District Court for the Eastern District of Virginia.

Operation Details and Arrests

The coordinated action against EvilTokens involved various partners and resulted in the arrest of two individuals in mid-September. These arrests were part of a broader strategy to dismantle what Microsoft described as a formidable cybercrime platform. Utilizing AI, EvilTokens helped cybercriminals analyze email accounts to identify opportunities for financial fraud and scams.

According to Steven Masada, a key official at Microsoft’s Digital Crimes Unit, the platform’s AI capabilities allowed criminals to understand victim relationships and devise fraudulent activities. This service was not only about account takeovers but also included AI-driven email analysis and fraud strategy development.

Phishing as a Service Model

Initially documented by Huntress in early 2026, EvilTokens operated under a phishing-as-a-service (PhaaS) model. It exploited OAuth 2.0 device authorization to access victim accounts invisibly. The service facilitated email data theft and allowed attackers to maintain access by setting deceptive inbox rules.

The service’s offerings included several products, such as the Office 365 capture link, which allowed affiliates to access Microsoft tokens for a fee. These features enabled attackers to personalize phishing lures and utilize AI to craft convincing phishing emails.

Impact and Future Security Measures

Microsoft’s data indicates that EvilTokens has compromised over 12,000 email inboxes globally, affecting organizations across various sectors. The geographical spread of victims includes countries like the U.S., Canada, and the U.K., among others. Targeted sectors range from finance to healthcare and education.

In collaboration with partners, Microsoft has deactivated 50 websites and over 150 domains linked to EvilTokens. This move is part of broader efforts to disrupt similar phishing services. SpyCloud, a partner in the operation, provided intelligence on compromised accounts, highlighting the extensive reach of EvilTokens.

While the dismantling of EvilTokens marks a significant step in combating phishing, it underscores the need for continued vigilance in cybersecurity. Microsoft’s intervention demonstrates the importance of collaborative efforts in tackling sophisticated cyber threats. As technology evolves, security measures must adapt to prevent similar threats in the future.

The Hacker News Tags:AI, cloud security, corporate security, cyber threats, Cybercrime, Cybersecurity, device code phishing, digital crimes, email security, EvilTokens, Microsoft, OAuth 2.0, PhaaS, Phishing, Storm-2992

Post navigation

Previous Post: Cisco Talos Unveils CAIRN to Combat Autonomous AI Malware
Next Post: BigCommerce Faces Data Breach Through Ribon Apps

Related Posts

Beyond Vulnerability Management – Can You CVE What I CVE? Beyond Vulnerability Management – Can You CVE What I CVE? The Hacker News
That Network Traffic Looks Legit, But it Could be Hiding a Serious Threat That Network Traffic Looks Legit, But it Could be Hiding a Serious Threat The Hacker News
Miasma Worm Affects 73 Microsoft GitHub Repositories Miasma Worm Affects 73 Microsoft GitHub Repositories The Hacker News
AI Arms Race: Prioritizing Unified Exposure Management AI Arms Race: Prioritizing Unified Exposure Management The Hacker News
Critical Cisco Email Vulnerability Actively Exploited Critical Cisco Email Vulnerability Actively Exploited The Hacker News
Gitea Patches Critical RCE Vulnerability in Git Hooks Gitea Patches Critical RCE Vulnerability in Git Hooks The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Aembit Integrates Okta’s Cross App Access for AI Control
  • Check Point Addresses Management Server Zero-Day Exploit
  • Critical Flaw in Check Point Servers Actively Exploited
  • BigCommerce Faces Data Breach Through Ribon Apps
  • Microsoft Dismantles AI-Powered Phishing Network EvilTokens

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Aembit Integrates Okta’s Cross App Access for AI Control
  • Check Point Addresses Management Server Zero-Day Exploit
  • Critical Flaw in Check Point Servers Actively Exploited
  • BigCommerce Faces Data Breach Through Ribon Apps
  • Microsoft Dismantles AI-Powered Phishing Network EvilTokens

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark