{"data":{"id":"a92f35a6-2be3-4d36-914d-5511871a928c","title":"Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises","summary":"Microsoft shut down EvilTokens, a phishing-as-a-service (PhaaS, a platform that sells phishing tools as a service) platform that used AI at every stage of attacks to compromise email accounts and commit fraud. The service exploited OAuth 2.0 device authorization (a legitimate login method that EvilTokens abused to trick users into granting attackers access to their accounts) to steal account tokens, then used an AI chatbot to analyze victims' inboxes, identify trusted contacts, and recommend fraud strategies. The takedown involved multiple organizations and law enforcement, resulting in the arrest of two men in connection with the operation.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://thehackernews.com/2026/09/microsoft-takes-down-eviltokens-device.html","publishedAt":"2026-09-22T17:03:31.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["prompt_injection","supply_chain"],"issueType":"news","affectedPackages":null,"affectedVendors":["OpenAI","Microsoft"],"affectedVendorsRaw":["Microsoft","OpenAI","Cloudflare","Coinbase","Railway","SpyCloud","TRM Labs","Health-ISAC","Shadowserver Foundation","Huntress","Sekoia"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-09-22T17:03:31.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}