EvilTokens takedown shows why cybercrime platforms are getting harder to stop
AI-summarised brief · reviewed before publication
Microsoft shut down the EvilTokens phishing-as-a-service platform after discovering it had compromised over 12,000 Microsoft 365 inboxes in more than 10,000 organizations worldwide. The service exploited device‑code phishing, abusing legitimate OAuth flows to bypass multi‑factor authentication. The takedown highlighted that cybercriminals can rapidly rebuild infrastructure using AI coding tools and inexpensive blockchain‑based services, making individual platform disruptions less effective. Coordinated, ecosystem‑wide action is now required to achieve lasting disruption.
💡 Why It Matters
- · The incident demonstrates that cybercrime operations can outpace traditional law‑enforcement responses, underscoring the need for proactive, collaborative defenses that target the underlying tools and infrastructure rather than isolated services.