Skip to content
Ars Technica·

🔒Microsoft Shuts Down EvilTokens, Disrupting 12,000 Accounts

Microsoft Takes Down EvilTokens, 12,000 Accounts Saved

TL;DR

Microsoft led an industry-wide disruption of EvilTokens, a platform that compromised 12,000 Microsoft accounts. The platform, introduced in February, charged $1,500 initially and $500 monthly, streamlining account compromises and post-compromise activities.

Microsoft has led an industry-wide disruption of EvilTokens, a platform that compromised 12,000 Microsoft accounts over a few-month span. EvilTokens, introduced in February, charged an initial $1,500 fee and a recurring $500 charge each month, streamlining the process of compromising email accounts in large numbers. The platform provided a single service for analyzing inboxes, selecting targets, and drafting follow-up emails, automating the sending of large numbers of spam and tailoring lures to the profiles of targeted organizations. Microsoft seized 50 websites and 150 more domains used to operate EvilTokens, and the UK's Metropolitan Police Service arrested two men on suspicion of offenses allegedly connected to the crime platform. This disruption highlights the shift in mass compromise and post-compromise of accounts, where attackers can now understand inbox contents in minutes, not days.

Microsoft Shuts Down EvilTokens, Disrupting 12,000 Accounts — Ars Technica

Key Points

1

EvilTokens compromised 12,000 Microsoft accounts over a few-month span.

2

The platform charged an initial $1,500 fee and a recurring $500 charge each month.

3

EvilTokens introduced in February over a Telegram channel.

4

Microsoft seized 50 websites and 150 more domains used to operate EvilTokens.

5

UK's Metropolitan Police Service arrested two men on suspicion of offenses connected to EvilTokens.

Why It Matters

If you're using Microsoft accounts, this is a big deal. EvilTokens compromised 12,000 accounts, streamlining the process of mass account compromise and post-compromise activities. This shift means attackers can now understand inbox contents in minutes, not days, highlighting the need for strong identity protections and independent verification of requests.

microsofteviltokenscybercrimeaccount-compromisesecurity-breach

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 3,489 builders reading daily.

Also get