Microsoft Disrupts EvilTokens Device Code Phishing Service

Microsoft and partners disrupted EvilTokens, a phishing-as-a-service operation that used AI and device code phishing to compromise more than 12,000 inboxes across over 10,000 organizations worldwide, underscoring how quickly identity attacks can scale into broad business email compromise risk. For CIOs and IT leaders, the incident reinforces that Microsoft 365 and identity controls are a front-line business resilience issue: organizations need stronger phishing-resistant authentication, tighter session/token monitoring, and faster detection of anomalous inbox and Graph API activity to limit financial fraud and lateral exposure.

Alexander CulafiDark Reading2 min read
Read full article
Microsoft Disrupts EvilTokens Device Code Phishing Service

Read the full story at Dark Reading →