WorkThe story, in brief

Microsoft takes down ‘EvilTokens’ cyber crime service

Microsoft disrupted EvilTokens, an AI-powered phishing service that targeted thousands of orgs in six months. Here's what it reveals about AI crime scaling.

Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
People, judgement and the changing nature of work.AI illustration by KeyNews
The KeyNews take

Why it matters

AI is lowering the barrier to entry for large-scale cyber attacks. This takedown shows how threat actors are operationalizing AI for social engineering at scale — a workplace security and policy concern for any organization running cloud infrastructure or handling credentials.

The key facts

10 to know
  1. EvilTokens used AI to target selection, impersonation, and exploitation strategy

  2. Hit thousands of organizations in six months

  3. Phishing-as-a-service model (democratized attack platform)

  4. Microsoft takedown action (law enforcement/platform response)

  5. Credential/token theft as the attack vector (cloud/identity security angle)

  6. EvilTokens operated for ~6 months before takedown

  7. Platform hit thousands of organizations globally

  8. Used AI to automate targeting, impersonation, and exploitation decisions

  9. Phishing-as-a-service model (platform democratizing attacks)

  10. Microsoft enforcement action (law enforcement/security vendor response)

Go to the source

ITProitpro.com

Publisher excerpt: In just six months, the EvilTokens phishing as a service platform hit thousands of organizations worldwide
Read original report
Back to today's editionMore work news

Keep reading

Related stories

More from Work