Microsoft disrupts AI phishing platform EvilTokens
Microsoft announced on Tuesday that it disrupted EvilTokens, an AI-powered phishing-as-a-service platform, under a U.S. court order, seizing 50 websites and disabling more than 150 domains tied to the operation while partners helped trace its infrastructure and finances. The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved HealthISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation and TRM Labs. Microsoft tracks the threat actors behind the platform as Storm2992. Microsoft said EvilTokens was linked to more than 12,000 compromised email inboxes across over 10,000 organizations worldwide, with victims concentrated in the United States, Canada, the United Kingdom, Australia, India and France. Targeted sectors included wholesale distribution, construction, financial services, real estate, higher education and healthcare. The figures come from Microsoft and its partners and have not been independently verified. In parallel, the Metropolitan Police Service arrested two men, aged 32 and 38, on suspicion of making articles for use in fraud and money laundering.