Microsoft announces it has disrupted the EvilTokens device-code phishing service, which it says enables criminals to compromise users’ inboxes. Microsoft says the service used AI throughout the attack chain and that the disruption follows authorization from the U.S. District Court for the Eastern District of Virginia.
Microsoft describes a coordinated effort led by Health-ISAC, working with multiple private-sector organizations, including Cloudflare and Coinbase. According to the reports, the action involves seizing infrastructure used to run the service—described as 50 websites—and disabling more than 150 domains linked to EvilTokens.
The outlets differ mainly in emphasis: one highlights that Microsoft characterizes the phishing operation as using AI at every step, while the other focuses more directly on the scale of reported impact. Help Net Security reports that EvilTokens compromised more than 12,000 inboxes across over 10,000 organizations, while both describe the same court-authorized, multi-partner disruption effort.