← Back to Feed
EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts
September 22, 2026 · BleepingComputer · Severity: MEDIUM
The EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft's Digital Crimes Unit (DCU).
Key Takeaways
- EvilTokens PhaaS campaign has been disrupted after compromising approximately 12,000 Microsoft accounts through token theft and phishing-as-a-service infrastructure.
- Phishing-as-a-service operations lower the barrier for credential theft by providing ready-made phishing kits and hosting infrastructure to aspiring attackers at low cost.
- Organizations should enforce phishing-resistant authentication methods such as FIDO2 security keys and monitor for anomalous token usage patterns to detect PhaaS-backed attacks.