Microsoft disrupts EvilTokens phishing service that gave criminals access to 12,000 inboxes

2026-09-23T08:51:39Z•10beb7bf3fa662ff66891146f11387a08dbcd6ebb6aeb427d9f226e1f24ef8e0
AI agentsAI securityEvilTokensLAPSUS$Microsoft disruptionNetBSDbot activitycredential theftcybercrimedeepfakesdomain hijackingdomain seizureinbox compromiseipfilterkernel vulnerabilitymalwarephishing-as-a-servicesocial engineering

What happened

Help Net Security reports on the disruption of the EvilTokens phishing-as-a-service operation, which compromised more than 12,000 inboxes across over 10,000 organizations. Microsoft and partners obtained court authorization to seize 50 operational websites and disable more than 150 related domains. The feed also covers emerging AI-agent security concerns, bot activity, deepfake-enabled social engineering, an AI-assisted malware research framework, a NetBSD ipfilter kernel vulnerability fix, and a brief Elsevier domain hijacking attributed to LAPSUS$ branding. No CVE identifiers are provided in

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
10beb7bf3fa662ff66891146f11387a08dbcd6ebb6aeb427d9f226e1f24ef8e0
Enrichment time
2026-09-23T08:51:39Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Microsoft disrupts EvilTokens phishing service that gave criminals access to 12,000 inboxes · Baitaphish