Urgent.News

What's breaking now, across thousands of outlets.

Tech

UK cops arrest 2 EvilTokens suspects, Microsoft seizes 50 phishing kit websites

Used by crims to compromise 12K+ email inboxes across 10K+ global orgs

UK cops arrest 2 EvilTokens suspects, Microsoft seizes 50 phishing kit websites

UK law enforcement and Microsoft have taken significant action against the EvilTokens phishing service. The coalition led by Microsoft has arrested two men suspected of being website administrators and seized over 50 websites used to operate the service. EvilTokens, a notorious Microsoft device-code phishing kit, has been used to compromise email accounts of 12,000 individuals across more than 10,000 organizations worldwide.

This particular phishing subscription was especially insidious due to its use of AI technology. The AI chatbot could analyze victims' inboxes, helping criminals identify targets, trusted contacts, and even the most effective fraud strategies. Microsoft's Digital Crimes Unit (DCU) has conducted this action, making it their 40th court-authorized disruption in nearly two decades.

The incident highlights the importance of strong identity protections and monitoring, as well as the need for organizations to independently verify requests for changes in payment information, fund redirections, or approvals of unusual transactions through a trusted second channel.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at theregister.com →

More in Tech

More from Tuesday 22 September →