$ techbeacon▋
Phishing

Microsoft Dismantles AI‑Powered EvilTokens Phishing Service After 12,000 Email Breaches

Microsoft Dismantles AI‑Powered EvilTokens Phishing Service After 12,000 Email Breaches

Microsoft announced on Tuesday that it has successfully taken down a phishing platform known as EvilTokens, which leveraged the Azure Active Directory device‑code authentication flow to steal credentials from an estimated 12,000 compromised inboxes.

The service operated by luring users into authorizing a malicious application via the device‑code process, a legitimate method that lets users sign in on devices without browsers. Attackers presented a counterfeit consent screen, prompting victims to enter a short code that granted the malicious app access to their accounts, effectively bypassing traditional password checks.

According to the company, artificial intelligence was embedded at every stage of the attack chain. Machine‑learning models generated realistic phishing pages, tailored messages to individual targets, and automated the harvesting and validation of stolen tokens. The AI component allowed the campaign to scale quickly and adapt to defensive measures in real time.

The takedown was executed with the explicit authorization of the United States District Court for the Eastern District of Virginia, reflecting close coordination between Microsoft’s cyber‑security teams and federal law‑enforcement agencies. Legal orders enabled the seizure of servers and infrastructure that hosted the phishing site, effectively halting further credential theft.

Security analysts note that the breach of 12,000 email accounts could have exposed sensitive corporate communications, personal data, and intellectual property. While the full extent of the damage remains under investigation, the incident underscores the growing risk posed by credential‑theft schemes that exploit legitimate authentication flows.

Microsoft said the operation is part of a broader initiative to disrupt credential‑harvesting ecosystems. The company has been investing in advanced detection tools that flag anomalous device‑code requests and is urging organizations to enforce multi‑factor authentication, especially for high‑privilege accounts.

Experts warn that the integration of AI into phishing attacks is likely to accelerate, making malicious campaigns harder to detect and more persuasive. They recommend continuous user education, regular monitoring of authentication logs, and swift revocation of any suspicious tokens as essential defenses against evolving threats.

Mahesh Kumar Sahoo — Mahesh covers ransomware gangs, data leak sites, and dark web marketplaces, mapping how stolen data surfaces and gets sold. Follows ShinyHunters-style groups across leak forums.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related