Tech News
← Home  ·  All topics

Device Code Phishing

2 GoKawiil briefs on this topic

Microsoft dismantles EvilTokens phishing service, two arrested in UK

Microsoft has shut down EvilTokens, a subscription-based cybercrime service sold via Telegram that used AI tools to break into Microsoft accounts and mine stolen inboxes for payment details and business contacts. The company said the service compromised roughly 12,000 accounts across 10,000 organizations by abusing Microsoft's device-code sign-in process, and it seized 50 websites and 150 domains via legal action. UK police separately arrested two men suspected of running the operation.

Microsoft seizes 50 EvilTokens phishing sites, two arrested in UK

Microsoft and partner organizations dismantled EvilTokens, a phishing-as-a-service operation that used AI tools and device code phishing to compromise over 12,000 inboxes across more than 10,000 organizations. Following a US court-enabled legal action, Microsoft seized 50 websites and disabled over 150 additional domains linked to the operators, tracked as Storm-2992. The UK's Metropolitan Police also arrested two men connected to the scheme this month; both were released on bail pending further investigation.