Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft Dismantles AI-Powered Phishing Network EvilTokens

Microsoft Dismantles AI-Powered Phishing Network EvilTokens

Posted on September 22, 2026 By CWS

Microsoft has dismantled the EvilTokens phishing service, a sophisticated operation leveraging artificial intelligence (AI) to orchestrate widespread email compromises. This takedown, announced on Tuesday, was executed with the aid of multiple partners, including Health-ISAC and Cloudflare. The initiative received legal backing from the U.S. District Court for the Eastern District of Virginia.

Operation Details and Arrests

The coordinated action against EvilTokens involved various partners and resulted in the arrest of two individuals in mid-September. These arrests were part of a broader strategy to dismantle what Microsoft described as a formidable cybercrime platform. Utilizing AI, EvilTokens helped cybercriminals analyze email accounts to identify opportunities for financial fraud and scams.

According to Steven Masada, a key official at Microsoft’s Digital Crimes Unit, the platform’s AI capabilities allowed criminals to understand victim relationships and devise fraudulent activities. This service was not only about account takeovers but also included AI-driven email analysis and fraud strategy development.

Phishing as a Service Model

Initially documented by Huntress in early 2026, EvilTokens operated under a phishing-as-a-service (PhaaS) model. It exploited OAuth 2.0 device authorization to access victim accounts invisibly. The service facilitated email data theft and allowed attackers to maintain access by setting deceptive inbox rules.

The service’s offerings included several products, such as the Office 365 capture link, which allowed affiliates to access Microsoft tokens for a fee. These features enabled attackers to personalize phishing lures and utilize AI to craft convincing phishing emails.

Impact and Future Security Measures

Microsoft’s data indicates that EvilTokens has compromised over 12,000 email inboxes globally, affecting organizations across various sectors. The geographical spread of victims includes countries like the U.S., Canada, and the U.K., among others. Targeted sectors range from finance to healthcare and education.

In collaboration with partners, Microsoft has deactivated 50 websites and over 150 domains linked to EvilTokens. This move is part of broader efforts to disrupt similar phishing services. SpyCloud, a partner in the operation, provided intelligence on compromised accounts, highlighting the extensive reach of EvilTokens.

While the dismantling of EvilTokens marks a significant step in combating phishing, it underscores the need for continued vigilance in cybersecurity. Microsoft’s intervention demonstrates the importance of collaborative efforts in tackling sophisticated cyber threats. As technology evolves, security measures must adapt to prevent similar threats in the future.

The Hacker News Tags:AI, cloud security, corporate security, cyber threats, Cybercrime, Cybersecurity, device code phishing, digital crimes, email security, EvilTokens, Microsoft, OAuth 2.0, PhaaS, Phishing, Storm-2992

Post navigation

Previous Post: Cisco Talos Unveils CAIRN to Combat Autonomous AI Malware
Next Post: BigCommerce Faces Data Breach Through Ribon Apps

Related Posts

Microsoft Addresses GitHub Security Breach Amid Ongoing Probe Microsoft Addresses GitHub Security Breach Amid Ongoing Probe The Hacker News
Password Reuse in Disguise: An Often-Missed Risky Workaround Password Reuse in Disguise: An Often-Missed Risky Workaround The Hacker News
Chinese Group Silver Fox Uses Fake Websites to Deliver Sainbox RAT and Hidden Rootkit Chinese Group Silver Fox Uses Fake Websites to Deliver Sainbox RAT and Hidden Rootkit The Hacker News
WeChat Security Flaw Exploited via Zero-Click Worm WeChat Security Flaw Exploited via Zero-Click Worm The Hacker News
MongoDB Vulnerability CVE-2025-14847 Under Active Exploitation Worldwide MongoDB Vulnerability CVE-2025-14847 Under Active Exploitation Worldwide The Hacker News
Trivy Security Breach: 75 Tags Compromised in GitHub Actions Trivy Security Breach: 75 Tags Compromised in GitHub Actions The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Flaw in Check Point Servers Actively Exploited
  • BigCommerce Faces Data Breach Through Ribon Apps
  • Microsoft Dismantles AI-Powered Phishing Network EvilTokens
  • Cisco Talos Unveils CAIRN to Combat Autonomous AI Malware
  • AI Agents Exploit Retailers, Steal 600,000 Credit Cards

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Flaw in Check Point Servers Actively Exploited
  • BigCommerce Faces Data Breach Through Ribon Apps
  • Microsoft Dismantles AI-Powered Phishing Network EvilTokens
  • Cisco Talos Unveils CAIRN to Combat Autonomous AI Malware
  • AI Agents Exploit Retailers, Steal 600,000 Credit Cards

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark