Microsoft takes down AI-boosted phishing tool that hit 12,000 accounts

https://cdn.mos.cms.futurecdn.net/j5YMwZuuKnvAXLyKBEmDrb-970-80.jpg
  • Microsoft, UK police, and partners disrupted EvilTokens PhaaS, arresting two suspects and seizing 200+ domains/sites
  • EvilTokens used AI to scale device‑code phishing, compromising 12,000 inboxes across 10,000 organizations globally
  • Platform ran like a startup with subscriptions, dashboards, and AI‑driven targeting; US victims hit hardest

Two people have been arrested, 50 websites were seized, and 150 domains disabled, in a joint operation against the infamous EvilTokens phishing-as-a-service (PhaaS) kit.

In its report, Microsoft said the UK Metropolitan Police Service’s cybercrime team “arrested two men on suspicion of offenses connected with the alleged operation of EvilTokens.”

The two men, whose identities were not disclosed, are aged 32 and 38, and have been released on bail, subject to conditions while the investigation continues. Their digital services and other items have been confiscated, as well.

Among the partners are Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs. We don’t...

Copyright of this story solely belongs to www.techradar.com. To see the full text click HERE

Read more