A coalition led by Microsoft and law enforcement agencies in the US and UK has disrupted EvilTokens, a phishing service used by criminals to steal access to Microsoft 365 accounts.
The service first appeared in February and was used to compromise around 12,000 email accounts across more than 10,000 organizations worldwide. EvilTokens was sold as a subscription and helped criminals bypass multi-factor authentication (MFA) and access victims’ Microsoft 365 accounts. The service also used AI to analyze victims’ emails helping criminals find important contacts, choose people to impersonate, and plan scams.
As part of the operation, Microsoft seized more than 50 websites and disabled over 150 other domains linked to EvilTokens.
On September 18, London’s Metropolitan Police arrested two men, aged 32 and 38, who are suspected of running the service. Both were released on bail while the investigation continues.
Authorities and Microsoft have also contacted victims whose email accounts may have been compromised.