Dark Reading

Microsoft Disrupts EvilTokens Device Code Phishing Service

PhishingHighphishing

Microsoft disrupted EvilTokens, a phishing-as-a-service platform targeting Microsoft 365 accounts, by seizing 50 websites and disabling 150+ domains. The action targets automated credential theft attacks leveraging device code authentication flows. This matters to security professionals managing email and cloud identity threats.

AI summary · generated with Claude

https://www.darkreading.com/identity-access-management-security/microsoft-disrupts-eviltokens-device-code-phishing-service