← registry

Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises

Microsoft disrupted an AI-powered phishing service called EvilTokens that leveraged device-code authentication attacks to compromise approximately 12,000 email inboxes, with AI integrated throughout the attack workflow.

Categorymisuse
Severityhigh
AI systemother
Sectorstechnologyfinancegovernment
Harm typessecurityprivacyfinancial
Actorexternal_attacker
Published2026-09-22 17:03:31

Summary is Secursion's own; full text lives at the source. Attribution preserved.