Microsoft disrupts AI-assisted platform that compromised 12,000
Microsoft and Coinbase disrupted the EvilTokens cybercrime operation, a platform tied to 12,000 inbox compromises. The takedown of the AI-assisted service involved an investigation that led to arrests of the operators behind the DIY phishing network. EvilTokens utilized device code phishing techniques to compromise user accounts, highlighting the growing threat of artificial intelligence in cybercrime infrastructure. The action stripped the malicious platform of access to its essential infrastructure.
Listen to Live Briefing
Real-time synthesized voice briefing · Live Feeds Desk
- ✓ Microsoft disrupted the EvilTokens platform, which was tied to 12,000 inbox compromises.
- ✓ A joint probe by Microsoft and Coinbase led to the arrest of the individuals behind EvilTokens.
- ✓ EvilTokens operated as an AI-assisted, DIY phishing network.
- ✓ The service utilized device code phishing.
What changed
Microsoft and Coinbase dismantled the EvilTokens phishing network and arrested the operators behind the platform.
Live updates
-
Microsoft Disrups EvilTokens Phishing Service
Microsoft and Coinbase disrupted the EvilTokens cybercrime operation, a platform tied to 12,000 inbox compromises. The takedown of the AI-assisted service involved an investigation that led to arrests of the operators behind the DIY phishing network. EvilTokens utilized device code phishing techniques to compromise user accounts, highlighting the growing threat of artificial intelligence in cybercrime infrastructure. The action stripped the malicious platform of access to its essential infrastructure.
Why it matters
Device code phishing attacks target authentication flows by tricking users into authorizing malicious devices. The disruption of EvilTokens offers a window into how threat actors leverage artificial intelligence tools to scale attacks. Security researchers continue to analyze the operation to understand the full extent of AI integration in modern cybercrime.
What is confirmed
- Microsoft disrupted the EvilTokens platform, which was tied to 12,000 inbox compromises.
- A joint probe by Microsoft and Coinbase led to the arrest of the individuals behind EvilTokens.
- EvilTokens operated as an AI-assisted, DIY phishing network.
- The service utilized device code phishing.
What to watch next
- Further details on the identities of the arrested suspects
- Additional law enforcement actions against related AI-powered phishing networks
confidence 95%Sources used for this update (7)
- Ars Technica — Microsoft disrupts AI-assisted platform that compromised 12,000
- Microsoft — Unmasking EvilTokens: Getting to the root of device code phishing
- csoonline.com — Microsoft’s EvilTokens takedown sheds light on state of AI-powered cybercrime
- Coinbase — Consumer Protection Tuesday: Taking Down Evil Tokens
- The Hacker News — Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
- Fortune — Microsoft and Coinbase probe leads to arrest of crooks behind 'EvilTokens', a DIY phishing network powered by AI
- Axios — A major AI-powered phishing service has lost access to its key infrastructure
Community Sentiment: How do you assess this situation?
Voice your perspective · Real-time aggregated sentiment from the Live Feeds community