Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Microsoft Disrupts AI‑Powered EvilTokens Service After Compromising 12,000 Inboxes

Microsoft took down EvilTokens, an AI‑powered phishing‑as‑a‑service platform that had breached 12,000 email inboxes across 10,000 organizations. The service enabled sophisticated financial fraud, highlighting gaps in email‑security controls and user awareness that must be addressed for audit readiness.

LiveThreat™ Intelligence · 📅 September 24, 2026· 📰 hackread.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
4 recommended
📰
Source
hackread.com

Microsoft Disrupts AI‑Powered EvilTokens Phishing Service After Compromising 12,000 Inboxes

What Happened – Microsoft announced the takedown of EvilTokens, an AI‑driven phishing‑as‑a‑service platform that had compromised roughly 12,000 email inboxes across 10,000 organizations. The service leveraged large‑language models to craft convincing spear‑phishing messages, which were then used to conduct sophisticated financial fraud.

Why It Matters for Trust & Control Assurance

  • The incident illustrates the need for continuous monitoring of email‑security controls and real‑time evidence that anti‑phishing defenses are operating as intended.
  • It underscores the importance of security‑awareness programs that train users to recognize AI‑generated lures, providing a defensible audit trail of awareness activities.

Who Is Affected – Financial services firms, technology SaaS providers, and retail enterprises that rely on corporate email for transaction approvals and sensitive communications.

Recommended Actions

  • Enforce multi‑factor authentication (MFA) on all mailbox access points.
  • Deploy AI‑aware phishing detection solutions and integrate them with a centralized logging platform for continuous evidence collection.
  • Conduct regular security‑awareness simulations that include AI‑generated phishing scenarios.
  • Review and harden email gateway policies (DMARC, SPF, DKIM) to reduce spoofing risk.

Technical Notes – EvilTokens used large‑language‑model generation to automate spear‑phishing content, bypassing traditional keyword‑based filters. Compromised credentials were harvested from the inboxes, enabling Business Email Compromise (BEC) attacks and fraudulent wire transfers. Source: HackRead

📰 Original Source
https://hackread.com/microsoft-disrupts-ai-powered-eviltokens-service/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →