Microsoft and industry partners disrupted EvilTokens, a phishing-as-a-service platform tied to more than 12,000 compromised Microsoft customer email inboxes across over 10,000 organizations worldwide. The operation used AI-driven tools to support business-email compromise and financial fraud, while law enforcement arrested two suspected operators in the U.K. and seized key infrastructure. #EvilTokens #Microsoft #Storm-2992 #FelixUtomi #WaidiSegunAdams
Keypoints
- Microsoft and partners seized 50 websites and disabled more than 175 domains linked to EvilTokens.
- EvilTokens used AI to analyze inboxes, identify targets, and support fraud campaigns.
- The platform was linked to more than 12,000 compromised Microsoft email inboxes and over 10,000 organizations.
- Two suspected operators, Felix Utomi and Waidi Segun Adams, were arrested in the United Kingdom.
- EvilTokens facilitated business-email compromise, MFA bypass, and financial theft through subscription-based access.
Read More: https://cyberscoop.com/microsoft-eviltokens-cybercrime-service-takedown/