HackerFeeds

CyberSecurity News

Microsoft Disrupts EvilTokens Device Code Phishing Service

Dark Reading
· September 22, 2026

AI summary

Microsoft has taken action against a phishing-as-a-service platform, seizing 50 websites and disabling over 150 domains. The target of this platform was Microsoft 365 accounts, with the service being known as EvilTokens Device Code Phishing. This effort was a coordinated disruption aimed at stopping the phishing operation. The action is intended to prevent further phishing attempts against Microsoft 365 users. The phishing platform relied on device code phishing to gain unauthorized access to accounts. Microsoft's disruption is a significant move to protect its users from this type of threat.

Read the full article at Dark Readingwww.darkreading.com/identity-access-management-security/microsoft-disrupts-eviltokens-device-code-phishing-service

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to Dark Reading.