:

MICROSOFT DISRUPTS EVILTOKEN PHISHING SERVICE

INDUSTRY DESK1 MIN READ
TUE, SEP 22, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Microsoft's Digital Crimes Unit has shut down EvilTokens, a phishing-as-a-service platform that compromised over 12,000 Microsoft accounts across 10,000+ organizations.

EvilTokens operated as a criminal service offering phishing infrastructure and token theft capabilities to threat actors. The platform enabled attackers to harvest authentication credentials at scale, providing unauthorized access to corporate and personal Microsoft accounts. Microsoft's DCU coordinated the disruption effort, taking down the service's infrastructure and blocking related malicious activities. The action marks a significant enforcement operation against a major credential theft operation. Accounts compromised through EvilTokens included enterprise email, cloud services, and collaboration platforms. Organizations affected have been notified and advised to review account access logs and implement additional authentication safeguards. The disruption demonstrates ongoing efforts by Microsoft and law enforcement to target phishing-as-a-service platforms that facilitate large-scale account compromise operations. Security researchers estimate such services have cost organizations millions in remediation and incident response costs.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Researchers have identified stolen credentials as a critical vulnerability threatening America's water infrastructure. The exposed passwords create direct pathways for attackers to access essential systems.

JUST NOWSecurity Desk

A webinar tomorrow examines critical early response decisions in Google Workspace breaches. Real-world incident analysis shows which actions limit damage and which escalate the impact.

1H AGOSecurity Desk

D-Link has alerted users of a maximum-severity zero-day vulnerability (CVE-2026-86296) affecting DIR-822A dual-band Wi-Fi routers. The flaw has no available patch and public exploit code is already circulating.

3H AGOSecurity Desk

A cross-site request forgery (CSRF) vulnerability in WordPress Core, dubbed 'Click2Shell,' enables attackers to execute PHP code on vulnerable servers. Technical details and working exploits are now public.

11H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.