Microsoft and partners take down EvilTokens, an AI-assisted device-code phishing service tied to 12,000 compromised inboxes
The Hacker News (corroborated by Axios, BleepingComputer and Ars Technica)·high signal
Microsoft and Health-ISAC, working with Cloudflare, Coinbase, OpenAI, Railway and others, seized 50 websites and disabled more than 150 domains belonging to EvilTokens. The service compromised over 12,000 inboxes at more than 10,000 organizations. It sold on Telegram for a $1,500 initiation fee plus $500 a month, abused device-code authentication, and used AI to find invoices, wire-transfer threads and employees able to move money. The Metropolitan Police arrested two men on September 11. Tenants that still allow device-code flow should restrict it.