www.securityweek.com 23 Sept 2026, 11:23 UTC

Microsoft Disrupts AI Phishing Platform That Stole 12,000 Accounts

Microsoft Disrupts AI Phishing Platform That Stole 12,000 Accounts
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor
EvilTokens

MICROSOFT says it has disrupted EvilTokens, an AI-powered phishing platform that emerged in February 2026 and was used to compromise more than 12,000 email accounts across over 10,000 organisations. Reported targets included organisations in the US, Canada, the UK, Australia, India and France. The service abused device-code authentication, a flow intended for devices such as televisions and printers that do not support standard logins.

Attackers sent victims a code through phishing messages; if the victim entered it in a browser, the attacker could receive an access token without obtaining the password.

According to Microsoft, EvilTokens used artificial intelligence to create personalised phishing emails and pages, offering 44 themes, and to analyse compromised inboxes for valuable information and relationships that could be exploited. Microsoft also believes AI was used to develop the platform itself. Criminal users paid $1,500 for initial access and $500 per month. Microsoft seized 50 websites running the service and disabled more than 150 additional domains linked to its infrastructure.

The company said the operation had also led to the arrest in the UK of two men, Felix Utomi and Waidi Segun Adams, whom it suspects were linked to EvilTokens. They were named in a Microsoft complaint that also targets five unnamed individuals. SpyCloud, TRM Labs, Coinbase, Health-ISAC, Cloudflare, OpenAI, Railway and The Shadowserver Foundation contributed to the disruption.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline