← Back to Feed

EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts

September 22, 2026 · BleepingComputer · Severity: MEDIUM

The EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft's Digital Crimes Unit (DCU).

Key Takeaways

  • EvilTokens PhaaS campaign has been disrupted after compromising approximately 12,000 Microsoft accounts through token theft and phishing-as-a-service infrastructure.
  • Phishing-as-a-service operations lower the barrier for credential theft by providing ready-made phishing kits and hosting infrastructure to aspiring attackers at low cost.
  • Organizations should enforce phishing-resistant authentication methods such as FIDO2 security keys and monitor for anomalous token usage patterns to detect PhaaS-backed attacks.
☕ Buy a Coffee