conv.

All stories
SecurityActive · 36h

Microsoft dismantles EvilTokens, an AI-driven phishing platform, two men arrested

A subscription-based scam service used an AI chatbot to help criminals hijack 12,000 Microsoft accounts before a coordinated takedown.

What to know

  • Microsoft says EvilTokens compromised 12,000 accounts at 10,000 organizations, with the heaviest concentration in the US.
  • The service used an AI chatbot to analyze victim inboxes and craft impersonation emails, and abused legitimate OAuth device code authentication to hijack accounts.
  • Microsoft seized 50 websites and disabled over 150 domains; UK police arrested two men in connection with the platform.

“The platform could even recommend fraud strategies, including drafting messages that impersonated trusted contacts to help criminals trick victims into taking action.”

Microsoft, Company statement · Ars Technica ↗ · Sep 21

Microsoft Investigating companySpyCloud Security firmUK Metropolitan Police Service Law enforcementDan Goodin Ars Technica security reporter

Microsoft dismantles EvilTokens, an AI-driven phishing platform, two men arrested
arstechnica.com

How it unfolded 2 developments, newest first · click a bar or a number to jump articlesposts

Peak 9 pieces in one hour at Yesterday, 3 PM; 17 pieces over 37 hours (7 articles · 10 posts) Yesterday, 10 AM — 1 piece · 1 post — Mastodon 1Yesterday, 11 AM — quietYesterday, 12 PM — quietYesterday, 1 PM — quietYesterday, 2 PM — quietYesterday, 3 PM — 9 pieces · 7 articles · 2 posts — Google News 4, Mastodon 3, Newswires 2Yesterday, 4 PM — quietYesterday, 5 PM — quietYesterday, 6 PM — 1 piece · 1 post — Mastodon 1Yesterday, 7 PM — quietYesterday, 8 PM — quietYesterday, 9 PM — quietYesterday, 10 PM — quietYesterday, 11 PM — quietToday, 12 AM — 1 piece · 1 post — Mastodon 1Today, 1 AM — quietToday, 2 AM — 2 pieces · 2 posts — Bluesky 1, Hacker News 1Today, 3 AM — quietToday, 4 AM — quietToday, 5 AM — quietToday, 6 AM — 2 pieces · 2 posts — Bluesky 1, Mastodon 1Today, 7 AM — quietToday, 8 AM — quietToday, 9 AM — quietToday, 10 AM — 1 piece · 1 post — Mastodon 1Today, 11 AM — quietToday, 12 PM — quietToday, 1 PM — quietToday, 2 PM — quietToday, 3 PM — quietToday, 4 PM — quietToday, 5 PM — quietToday, 6 PM — quietToday, 7 PM — quietToday, 8 PM — quietToday, 9 PM — quietToday, 10 PM — quiet ◂ 1 earlier2
4 PMtoday8 AM4 PMnow · 11:21 PM ET
  1. 2

    Researchers detail device-code OAuth abuse behind the scheme

    Microsoft and security firm SpyCloud described how EvilTokens automated spam emails that led victims to pages running hidden scripts to generate device authentication codes via Microsoft Entra, letting attackers enroll their own devices and evade signature-based detection.

    “While EvilTokens helped cybercriminals access email accounts, at the center of the service was an AI-style chatbot that could analyze a victim's inbox and help criminals identify trusted relationships, payment authorizations, and sensitive responsibilities, as well as other circumstances where fraud was most likely to succeed.”
    — Microsoft, Company statement · source
    • romanpiso.bsky.social

      #Discover #Security #Privacy #Microsoft #AI #DataCenters #Platform #CompromisedAccounts #Cybersecurity #Tech #TechNews

      romanpiso.bsky.socialBluesky20h ago5▲view on Bluesky ↗
  2. 1

    Microsoft seizes EvilTokens infrastructure, two men arrested

    Microsoft announced Tuesday it led a legal and technical operation seizing 50 websites and disabling more than 150 domains used to run EvilTokens; the UK's Metropolitan Police Service arrested two men on suspicion of offenses connected to the platform.

    1. first by The Hacker News, 1d ago · also Dark Reading

      1 more headline
  3. background

    EvilTokens phishing-as-a-service launches on Telegram — The platform was advertised over a Telegram channel, charging an initial $1,500 fee plus a recurring $500 monthly charge, offering an end-to-end toolkit for compromising Microsoft 365 email accounts.

Also covered reported alongside — the timeline has no entry for these yet

  1. first by Mastodon, 1d ago · also Ars Technica

    1 more headline

and 2 smaller pieces