Microsoft’s AI-powered Attack on EvilTokens

Microsoft’s AI-powered Attack on EvilTokens

Microsoft's disruption of EvilTokens has removed a significant threat to global organizations.

Bottom line: Microsoft's disruption of EvilTokens has removed a significant threat to global organizations.

What's happening: EvilTokens, linked to over 12,000 compromised Microsoft 365 inboxes in 10,000+ organizations worldwide, was disrupted since February 2026. The platform offered a subscription-based PhaaS service. On February 10, 2026, Microsoft began takedown operations.

What to do: Security teams should review their Microsoft 365 defenses to ensure they are not vulnerable to similar attacks.

Source: CSO Online