EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts
BLUF
Microsoft DCU took down a major phishing service that had already compromised 12,000+ accounts globally.
NEWS
The EvilTokens Phishing-as-a-Service platform was dismantled following an investigation by Microsoft's Digital Crimes Unit. Prior to disruption, the operation had successfully breached more than 12,000 Microsoft accounts belonging to over 10,000 distinct organizations.
Why I Care
Organizations using Microsoft services remain vulnerable to similar PhaaS tools even after this takedown, as attackers may migrate or replicate the infrastructure. The scale of compromise highlights the ongoing risk of token-based phishing attacks targeting cloud identities.
Next Steps
Security teams should audit all Microsoft account activity for signs of token abuse immediately. Implement Conditional Access policies to restrict legacy authentication and enforce MFA. Monitor for new PhaaS indicators of compromise shared by Microsoft DCU within the next 48 hours.
Source: BleepingComputer ·