:

MICROSOFT DISRUPTS EVILTOKEN PHISHING SERVICE

INDUSTRY DESK1 MIN READ
TUE, SEP 22, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Microsoft's Digital Crimes Unit has shut down EvilTokens, a phishing-as-a-service platform that compromised over 12,000 Microsoft accounts across 10,000+ organizations.

EvilTokens operated as a criminal service offering phishing infrastructure and token theft capabilities to threat actors. The platform enabled attackers to harvest authentication credentials at scale, providing unauthorized access to corporate and personal Microsoft accounts. Microsoft's DCU coordinated the disruption effort, taking down the service's infrastructure and blocking related malicious activities. The action marks a significant enforcement operation against a major credential theft operation. Accounts compromised through EvilTokens included enterprise email, cloud services, and collaboration platforms. Organizations affected have been notified and advised to review account access logs and implement additional authentication safeguards. The disruption demonstrates ongoing efforts by Microsoft and law enforcement to target phishing-as-a-service platforms that facilitate large-scale account compromise operations. Security researchers estimate such services have cost organizations millions in remediation and incident response costs.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

An IT mistake at English hospitals resulted in the loss of 11 years of viewing history for maternity patient records. Hospital staff recovered the underlying patient care data, though access logs remain unrecoverable.

JUST NOWIndustry Desk

A new Windows malware called ClosedQuorum leverages multiple AI models to autonomously decide its attack strategy after gaining system access. The threat uses Google Gemini, DeepSeek, Qwen, and Mistral to determine post-compromise actions.

JUST NOWAI Desk

Researchers have identified stolen credentials as a critical vulnerability threatening America's water infrastructure. The exposed passwords create direct pathways for attackers to access essential systems.

2H AGOSecurity Desk

A webinar tomorrow examines critical early response decisions in Google Workspace breaches. Real-world incident analysis shows which actions limit damage and which escalate the impact.

3H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.