InfoSec News Nuggets – 09/24/2026
Brief
Microsoft disrupts EvilTokens phishing service that gave criminals access to 12,000 inboxes
A coalition led by Microsoft and Health-ISAC has shut down EvilTokens. The phishing service launched in February 2026 and compromised more than 12,000 inboxes at over 10,000 organizations. With a court order from the Eastern District of Virginia, and help from partners including Cloudflare, Coinbase, OpenAI, and Shadowserver, investigators seized 50 websites and disabled more than 150 domains.
EvilTokens used device-code phishing, which tricks victims into entering an authentication code on Microsoft’s real sign-in page. That handed attackers access that could survive a password reset. An AI chatbot then read through the stolen mailboxes to find wire transfer talks, vendor invoices, and the best people to impersonate. The service sold on Telegram for a $1,500 sign-up fee plus $500 a month.
