EvilTokens made phishing-as-a-service look easy. Then it got taken down
Microsoft, Coinbase and law enforcement took down EvilTokens, a phishing kit that compromised 12,000 inboxes through device-code phishing and AI. EvilTokens showed up in February 2026 and moved fast. Within months it had compromised more than 12,000 inboxes across over 10,000 organizations. Microsoft says the EvilToken…
Short extract only — this publisher licenses its text. Read the full release at the source.
More from Security Affairs
- U.S. CISA adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog
- F5 BIG-IP APM Zero-Day Exploited in Zero-Day RCE Attacks
- ShinyHunters claims FBI breach after alleged PeopleSoft zero-day attack
The rest of this wire is for subscribers
Every release from this source, the moment it crosses — plus 80+ other newswires, saved searches and instant alerts.
7 days, no card required.
Read releases like this the second they cross the wire.
1,400+ feeds — live on PPN World right now. Every release from this source, the moment it crosses — plus 80+ other newswires, saved searches and instant alerts.
Start the free trial →Your announcement next? Distribute your press release to the global wires with PPN Source — and track its pickup live here.
PPN Source →