
EvilTokens Phishing-as-a-Service Platform Disrupted by Microsoft DCU
Microsoft's Digital Crimes Unit, in coordination with law enforcement partners, has disrupted the EvilTokens Phishing-as-a-Service (PhaaS) platform. The operation compromised credentials of over 12,000 Microsoft accounts across more than 10,000 organizations. The platform facilitated credential phishing attacks targeting Microsoft accounts and enabled the theft of session tokens. No software patch is required; affected organizations are advised to rotate compromised credentials and enable multi-factor authentication.
