importantSYS.SOURCE: The Hacker News• 2026-09-22T22:33:31+05:30
Microsoft Disables AI-Powered EvilTokens Device-Code Phishing Platform Linked to 12,000 Email Compromises
Microsoft dismantled the AI-driven EvilTokens phishing service, which exploited device code authentication to compromise over 12,000 email inboxes. The operation involved multiple cybersecurity partners and law enforcement, targeting a PhaaS platform that streamlined business email compromise attacks.
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every step of the attack chain."
The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved the efforts of Health-ISAC, alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver
*** END OF TRANSMISSION ***