Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
Summary
Microsoft shut down EvilTokens, a phishing-as-a-service (PhaaS, a platform that sells phishing tools as a service) platform that used AI at every stage of attacks to compromise email accounts and commit fraud. The service exploited OAuth 2.0 device authorization (a legitimate login method that EvilTokens abused to trick users into granting attackers access to their accounts) to steal account tokens, then used an AI chatbot to analyze victims' inboxes, identify trusted contacts, and recommend fraud strategies. The takedown involved multiple organizations and law enforcement, resulting in the arrest of two men in connection with the operation.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://thehackernews.com/2026/09/microsoft-takes-down-eviltokens-device.html
First tracked: September 22, 2026 at 02:00 PM
Classified by LLM (prompt v3) · confidence: 92%