Gbhackers iconGbhackersSep 23, 2026

Microsoft Warns of EvilTokens AI Phishing Service Hijacking Thousands of Accounts

Microsoft has warned that the EvilTokens phishing-as-a-service platform has become a major driver of AI-enabled device-code phishing, compromising more than 12,000 email inboxes across over 10,000 organizations worldwide since emerging in February 2026. The operation, linked to the threat actor Microsoft tracks as Storm-2992, industrializes token theft, mailbox reconnaissance, and business email compromise at scale […]

Microsoft Warns of EvilTokens AI Phishing Service Hijacking Thousands of Accounts

Share this story

Send the public story page.

Useful takeaways from this story.

The operation, linked to the threat actor Microsoft tracks as Storm-2992, industrializes token theft, mailbox reconnaissance, and business email compromise at scale […]

Microsoft has warned that the EvilTokens phishing-as-a-service platform has become a major driver of AI-enabled device-code phishing, compromising more than 12,000 email inboxes across over 10,000...

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

The operation, linked to the threat actor Microsoft tracks as Storm-2992, industrializes token theft, mailbox reconnaissance, and business email compromise at scale […] Microsoft has warned that the EvilTokens phishing-as-a-service platform has become a major driver of AI-enabled device-code phishing, compromising more than 12,000 email inboxes across over 10,000 organizations worldwide since emerging in February 2026.

Example or evidence

  • Microsoft has warned that the EvilTokens phishing-as-a-service platform has become a major driver of AI-enabled device-code phishing, compromising more than 12,000 email inboxes across over 10,000...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app