Microsoft dismantles EvilTokens phishing service, two arrested in UK
Microsoft has shut down EvilTokens, a subscription-based cybercrime service sold via Telegram that used AI tools to break into Microsoft accounts and mine stolen inboxes for payment details and business contacts. The company said the service compromised roughly 12,000 accounts across 10,000 organizations by abusing Microsoft's device-code sign-in process, and it seized 50 websites and 150 domains via legal action. UK police separately arrested two men suspected of running the operation.
GoKawiil's interpretation of the reporting above, not reported fact.
The case shows how device-code authentication, designed for low-input devices like TVs, can be weaponized at scale when paired with automated phishing infrastructure and AI-driven inbox analysis. Microsoft and SpyCloud's findings suggest that dynamic, script-based phishing kits can slip past detection systems built around static signatures, which may push defenders toward behavior-based monitoring. The takedown also illustrates a growing pattern of tech companies pairing legal domain seizures with law enforcement action to disrupt cybercrime-as-a-service operations.
- EvilTokens compromised about 12,000 Microsoft accounts across 10,000 organizations before being shut down.
- The service exploited OAuth device-code authentication, tricking victims into authorizing attacker-controlled devices.
- Microsoft seized 50 websites and 150 domains, while UK police arrested two men linked to the platform.
YubiKey 5 NFC Security Key — This article highlights how phishing and device-code authentication tricks can bypass typical login protections and hijack Microsoft accounts. A hardware security key like the YubiKey 5 NFC adds phishing-resistant multi-factor authentication that these kinds of social-engineering scams can't easily defeat. It's a simple, practical way to lock down your Microsoft, Google, or other accounts against exactly this type of attack.
See YubiKey 5 NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.Source: techspot.com — Skye Jacobs, 2026-09-23
Published there as: “Microsoft takes down EvilTokens service that used AI to turn stolen inboxes into payment fraud”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.