EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts

Refract AI Intelligence Digest

BLUF

Microsoft DCU took down a major phishing service that had already compromised 12,000+ accounts globally.

NEWS

The EvilTokens Phishing-as-a-Service platform was dismantled following an investigation by Microsoft's Digital Crimes Unit. Prior to disruption, the operation had successfully breached more than 12,000 Microsoft accounts belonging to over 10,000 distinct organizations.

Why I Care

Organizations using Microsoft services remain vulnerable to similar PhaaS tools even after this takedown, as attackers may migrate or replicate the infrastructure. The scale of compromise highlights the ongoing risk of token-based phishing attacks targeting cloud identities.

Next Steps

Security teams should audit all Microsoft account activity for signs of token abuse immediately. Implement Conditional Access policies to restrict legacy authentication and enforce MFA. Monitor for new PhaaS indicators of compromise shared by Microsoft DCU within the next 48 hours.

The EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft's Digital Crimes Unit (DCU). [...]
Back to Blog Listing

Source: BleepingComputer ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.