< Back to all clusters
[TECHNOLOGY] · United States, Canada, United Kingdom, Australia, India · 14 sources

started · updated

Microsoft and partners dismantle AI-powered EvilTokens phishing network

Microsoft, Cloudflare, and Coinbase, in coordination with international law enforcement, have dismantled EvilTokens, an AI-powered phishing-as-a-service platform. The operation targeted Microsoft 365 accounts by exploiting OAuth 2.0 device-code authentication to bypass multi-factor authentication (MFA).

EvilTokens operated via a subscription model on Telegram, charging a $1,500 setup fee and a $500 monthly fee. The platform utilized an integrated AI chatbot to analyze compromised inboxes, identify high-value targets, and draft convincing phishing lures to facilitate business email compromise. The service reportedly compromised over 12,000 email inboxes across more than 10,000 organizations in 79 countries, with high concentrations of victims in the US, Canada, UK, Australia, India, and France.

As part of the disruption, authorities seized 50 websites and disabled over 150 domains. In London, the Metropolitan Police arrested two men in connection with the operation. Financial forensics conducted by Coinbase traced approximately $1.1 million in illicit revenue across more than 700 deposit addresses.

Entities

Cloudflare · Coinbase · Digital Crimes Unit · EvilTokens · Health-ISAC · London · Metropolitan Police · Metropolitan Police Service · Microsoft

Claims

What the coverage asserts, and how many sources carry each claim.

Sources

about 7 hours ago
about 11 hours ago
about 14 hours ago