Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft Halts AI-Driven Phishing Network EvilTokens

Microsoft Halts AI-Driven Phishing Network EvilTokens

Posted on September 23, 2026 By CWS

Microsoft has successfully disrupted EvilTokens, an AI-driven phishing platform that has been a significant threat to numerous organizations globally. The announcement came on Tuesday, highlighting Microsoft’s ongoing commitment to cybersecurity.

Emergence and Impact of EvilTokens

Initially discovered in February 2026, EvilTokens has been implicated in the compromise of over 12,000 email accounts across more than 10,000 organizations. The affected areas include major regions such as the United States, Canada, the United Kingdom, Australia, India, and France. The scale of the threat underscores the widespread vulnerability posed by advanced phishing operations.

The platform enabled cybercriminals to exploit device code phishing techniques. This approach targets the authentication process for devices like TVs and printers that are not compatible with standard login methods. Users were tricked into entering an authentication code into a web session, unknowingly granting attackers access to their accounts.

AI’s Role in Enhancing Phishing Attacks

EvilTokens leveraged AI technology to craft highly targeted phishing emails, increasing the likelihood of deceiving recipients. The platform offered 44 distinct themes for these malicious emails, enhancing the personalization of attacks. Once infiltrated, AI tools assisted in sifting through victims’ inboxes for valuable information, optimizing the exploitation of relationships for financial gain.

Microsoft indicated that the platform itself might have been developed using AI methodologies. This integration of AI in both the creation and execution of phishing operations marks a significant evolution in cybercriminal tactics.

Disruption and Arrests Following the Takedown

To dismantle EvilTokens, Microsoft seized 50 operational websites and disabled over 150 domain names associated with the platform’s infrastructure. In addition to the technical measures, legal actions were taken against individuals suspected of running the platform.

Two suspects, Felix Utomi and Waidi Segun Adams, were apprehended in the United Kingdom. These individuals were named in a formal complaint by Microsoft, which also implicates five other unnamed individuals. This coordinated effort involved contributions from multiple organizations, including SpyCloud, TRM Labs, and others.

The dismantling of EvilTokens serves as a reminder of the persistent threat posed by AI-enhanced cybercrime. As technology evolves, so do the methods employed by cybercriminals, necessitating continuous vigilance and innovation in cybersecurity measures.

Security Week News Tags:AI, Cyberattack, Cybercrime, Cybersecurity, email security, EvilTokens, Microsoft, Phishing, Security, tech news

Post navigation

Previous Post: XRanges for AI: Revolutionizing Security Agent Evaluation
Next Post: NVIDIA Patches Critical Linux Vulnerabilities

Related Posts

Mercedes F1 Team Principal Toto Wolff Sells 15% Stake to CrowdStrike CEO George Kurtz Mercedes F1 Team Principal Toto Wolff Sells 15% Stake to CrowdStrike CEO George Kurtz Security Week News
iMessage Zero-Click Attacks Suspected in Targeting of High-Value EU, US Individuals iMessage Zero-Click Attacks Suspected in Targeting of High-Value EU, US Individuals Security Week News
MITRE Updates List of Most Common Hardware Weaknesses MITRE Updates List of Most Common Hardware Weaknesses Security Week News
Chinese Hackers Exploiting React2Shell Vulnerability Chinese Hackers Exploiting React2Shell Vulnerability Security Week News
CyberNut Closes M Growth Capital for K-12 Security Awareness Training CyberNut Closes $5M Growth Capital for K-12 Security Awareness Training Security Week News
Thousands of SaaS Apps Could Still Be Susceptible to nOAuth Thousands of SaaS Apps Could Still Be Susceptible to nOAuth Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical cPanel Security Flaws Threaten User Data
  • Outerlimit Secures $16M to Curb AI Agent Risks
  • AI-Driven Windows Malware Uses Voting System
  • Critical Vulnerability in Next.js Allows RCE via SVG
  • Exploring AI Threats: Potential Doomsday Scenarios

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical cPanel Security Flaws Threaten User Data
  • Outerlimit Secures $16M to Curb AI Agent Risks
  • AI-Driven Windows Malware Uses Voting System
  • Critical Vulnerability in Next.js Allows RCE via SVG
  • Exploring AI Threats: Potential Doomsday Scenarios

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark