Microsoft, Coinbase dismantle EvilTokens phishing network after 12,000 Microsoft 365 accounts compromised

  • Microsoft and Coinbase dismantled EvilTokens, a phishing service targeting Microsoft 365 accounts.
  • EvilTokens generated approximately $1.1 million through four Tron addresses between October 2025 and June 2026.
  • UK Metropolitan Police arrested the operators on September 11 and seized digital equipment.

Microsoft and Coinbase helped dismantle EvilTokens, a Telegram-based phishing-as-a-service platform internally tracked by Microsoft as Storm-2992, after it compromised more than 12,000 Microsoft 365 inboxes across over 10,000 organizations. The service exploited Microsoft’s legitimate device authorization grant flow to obtain persistent OAuth access without stealing passwords, allowing attackers to bypass the protection normally provided by multi-factor authentication. UK Metropolitan Police arrested the operators on September 11 and seized digital equipment. The disruption included the seizure of 50 websites and the disabling of more than 175 associated domains. Blockchain analysis found that EvilTokens generated approximately $1.1 million between October 2025 and June 2026 through four Tron addresses, receiving over 1,000 deposits from more than 700 unique sources. Coinbase said its platform credentials were not compromised, although some customers were manipulated through email into sending cryptocurrency to scammer-controlled addresses.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.