The record
Written from the 1 report below. Nothing here is unsourced.
- Microsoft successfully dismantled the EvilTokens phishing-as-a-service platform following a court-authorized operation.
- The service utilized AI to automate the analysis of compromised email inboxes and assisted attackers in conducting financial fraud.
- Victims were tricked into providing authentication codes through a legitimate Microsoft device login portal, granting attackers long-term account access.
- This disruption impacted over 12,000 compromised accounts across more than 10,000 organizations worldwide.
What to watch next
- Ongoing investigations into the Storm-2992 threat group
- Further disruptions of similar phishing-as-a-service platforms
- Monitoring of credential theft techniques involving OAuth 2.0 device authorization
Who said what2
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Steven Masada
associate general counsel
1 quote · 1 outlet
“While EvilTokens helped cybercriminals access email accounts, at the center of the service was an AI-style chatbot that could analyze a victim's inbox and help criminals identify trusted relationships, payment authorizations, and sensitive responsibilities, as well as other circumstances where fraud was most likely to succeed,”
In the article
…in connection with the illicit commercial operation. The tech giant described EvilTokens as a "powerful cybercrime platform" that used AI to compromise email accounts and design roadmaps for financial fraud and scams. " While EvilTokens helped cybercriminals access email accounts, at the center of the service was an AI-style chatbot that could analyze a victim's inbox and help criminals identify trusted relationships, payment authorizations, and sensitive responsibilities, as well as other circumstances where fraud was most likely to succeed, " Steven Masada, associate general counsel and general manager at Microsoft's Digital Crimes Unit, said. "The platform could even recommend fraud strategies, including drafting messages that impersonated trusted…
Trevor Hilligoss
SpyCloud's Chief Investigations Officer
1 quote · 1 outlet
“EvilTokens used AI to make the hard parts easy: reading compromised mailboxes in more than twenty languages to find the conversations worth hijacking, and drafting the impersonation mail that follows”
In the article
…data that included 8,708 unique victim accounts compromised by EvilTokens. These accounts span 6,585 unique corporate email domains located across 79 countries. The earliest captures date back to February 18, 2026. " EvilTokens used AI to make the hard parts easy: reading compromised mailboxes in more than twenty languages to find the conversations worth hijacking, and drafting the impersonation mail that follows ," Trevor Hilligoss, SpyCloud's Chief Investigations Officer, said in a statement. "Those were the parts of business email compromise that used to require human involvement, and that scaled with the skill of the…
Coverage1
All filed from India
Named United States · Canada · United Kingdom · Australia · India · France · Cloudflare · Coinbase · Health-ISAC · Huntress · Metropolitan Police Service · Microsoft · OpenAI · Railway · Sekoia · SpyCloud · Steven Masada · Storm-2992
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
