MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-22 · via BleepingComputer

Microsoft-led operation dismantles phishing service that breached thousands of accounts

Image via BleepingComputer
Image via BleepingComputer

Microsoft's Digital Crimes Unit coordinated a takedown of the EvilTokens phishing-as-a-service platform, which had compromised over 12,000 Microsoft accounts across more than 10,000 organizations. The service specialized in device-code phishing and offered AI-powered tools for crafting lures and scanning inboxes for high-value targets. Two suspects arrested in the U.K. were released on bail as the investigation continues.

Expanded Detail

The EvilTokens service operated on a subscription model, charging $500 monthly or a $1,500 one-time fee, with additional tools sold separately, including anti-bot redirectors and email-sending utilities. Subscribers could choose from 44 customizable phishing kits that impersonated document-signing platforms, invoicing systems, and Microsoft services, with lures ranging from construction bids to password-expiration warnings. After compromising an account, the platform leveraged Microsoft Graph to map organizational connections and used AI to scan mailbox contents for high-value targets. SpyCloud recovered data showing over 8,700 compromised accounts spanning 6,585 corporate domains across 79 countries, while the two arrested suspects, aged 32 and 38, were released on bail following warrants executed in Canary Wharf and Nine Elms.

Context

This takedown may signal a shift in how law enforcement addresses the growing commodification of cybercrime, where platforms like EvilTokens lower the technical barrier for attackers. Organizations relying solely on standard MFA could face continued risk, as device-code phishing exploits legitimate authentication flows that many security teams may not fully monitor. The AI-powered targeting features may also accelerate the sophistication of business email compromise, potentially affecting financial losses and data exposure across sectors like healthcare and construction.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts.” Browse more stories.