Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft Halts AI-Driven Phishing Network EvilTokens

Microsoft Halts AI-Driven Phishing Network EvilTokens

Posted on September 23, 2026 By CWS

Microsoft has successfully disrupted EvilTokens, an AI-driven phishing platform that has been a significant threat to numerous organizations globally. The announcement came on Tuesday, highlighting Microsoft’s ongoing commitment to cybersecurity.

Emergence and Impact of EvilTokens

Initially discovered in February 2026, EvilTokens has been implicated in the compromise of over 12,000 email accounts across more than 10,000 organizations. The affected areas include major regions such as the United States, Canada, the United Kingdom, Australia, India, and France. The scale of the threat underscores the widespread vulnerability posed by advanced phishing operations.

The platform enabled cybercriminals to exploit device code phishing techniques. This approach targets the authentication process for devices like TVs and printers that are not compatible with standard login methods. Users were tricked into entering an authentication code into a web session, unknowingly granting attackers access to their accounts.

AI’s Role in Enhancing Phishing Attacks

EvilTokens leveraged AI technology to craft highly targeted phishing emails, increasing the likelihood of deceiving recipients. The platform offered 44 distinct themes for these malicious emails, enhancing the personalization of attacks. Once infiltrated, AI tools assisted in sifting through victims’ inboxes for valuable information, optimizing the exploitation of relationships for financial gain.

Microsoft indicated that the platform itself might have been developed using AI methodologies. This integration of AI in both the creation and execution of phishing operations marks a significant evolution in cybercriminal tactics.

Disruption and Arrests Following the Takedown

To dismantle EvilTokens, Microsoft seized 50 operational websites and disabled over 150 domain names associated with the platform’s infrastructure. In addition to the technical measures, legal actions were taken against individuals suspected of running the platform.

Two suspects, Felix Utomi and Waidi Segun Adams, were apprehended in the United Kingdom. These individuals were named in a formal complaint by Microsoft, which also implicates five other unnamed individuals. This coordinated effort involved contributions from multiple organizations, including SpyCloud, TRM Labs, and others.

The dismantling of EvilTokens serves as a reminder of the persistent threat posed by AI-enhanced cybercrime. As technology evolves, so do the methods employed by cybercriminals, necessitating continuous vigilance and innovation in cybersecurity measures.

Security Week News Tags:AI, Cyberattack, Cybercrime, Cybersecurity, email security, EvilTokens, Microsoft, Phishing, Security, tech news

Post navigation

Previous Post: XRanges for AI: Revolutionizing Security Agent Evaluation
Next Post: NVIDIA Patches Critical Linux Vulnerabilities

Related Posts

Venezuelan Nationals Admit to ATM Jackpotting in US Venezuelan Nationals Admit to ATM Jackpotting in US Security Week News
Webinar Today: Why Context is a Secret Weapon in Application Security Posture Management Webinar Today: Why Context is a Secret Weapon in Application Security Posture Management Security Week News
175,000 Exposed Ollama Hosts Could Enable LLM Abuse 175,000 Exposed Ollama Hosts Could Enable LLM Abuse Security Week News
Hackers Agree to Erase Data Stolen From Canvas Platform Hackers Agree to Erase Data Stolen From Canvas Platform Security Week News
Pro-Russian Hackers Claim Cyberattack on French Postal Service Pro-Russian Hackers Claim Cyberattack on French Postal Service Security Week News
Claroty Raises 0 Million in Series F Funding Claroty Raises $150 Million in Series F Funding Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Vulnerability in Next.js Allows RCE via SVG
  • Exploring AI Threats: Potential Doomsday Scenarios
  • MemTensor Packages Breached to Deploy Credential Stealer
  • NVIDIA Patches Critical Linux Vulnerabilities
  • Microsoft Halts AI-Driven Phishing Network EvilTokens

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Vulnerability in Next.js Allows RCE via SVG
  • Exploring AI Threats: Potential Doomsday Scenarios
  • MemTensor Packages Breached to Deploy Credential Stealer
  • NVIDIA Patches Critical Linux Vulnerabilities
  • Microsoft Halts AI-Driven Phishing Network EvilTokens

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark