Microsoft disruption exposes AI-driven phishing-as-a-service
🔎 Microsoft says it disrupted EvilTokens, an AI-powered phishing-as-a-service platform that compromised over 12,000 Microsoft 365 inboxes across more than 10,000 organizations. Launched in February 2026, EvilTokens combined account compromise, mailbox analysis, target selection, and fraud preparation behind a subscription dashboard and chatbot. The operation abused Microsoft’s OAuth 2.0 device-code flow to steal session tokens and used an AI analyst to scan mailboxes and craft business email compromise scams. Microsoft seized infrastructure via a US court order and partners arrested two suspects in the UK amid coordinated takedown efforts.