Microsoft · Safety and security · OpenAI
Microsoft dismantled EvilTokens, which had compromised more than 12,000 inboxes
The device-code phishing service, which used AI at every step of the attack chain, was linked to more than 12,000 compromised inboxes across over 10,000 organizations. The operation, authorized by the US District Court for the Eastern District of Virginia, seized 50 sites and took down more than 150 supporting domains, with Cloudflare, Coinbase, OpenAI and others taking part. The service had sold since February for a $1,500 sign-up fee and $500 a month. An AI chatbot read victims’ messages, mapped internal roles and found conversations about payments. London police arrested two men on September 11.
Sources
- Microsoft On the Issues, “Disrupting EvilTokens: The AI Chatbot Built for Cybercrime”, (blogs.microsoft.com)
- Microsoft Security Blog, “Unmasking EvilTokens: Getting to the root of device code phishing”, (microsoft.com)
About this story
This story was posted on Instagram by @jarrus.tech on Sept. 27, 2026.
Spotted an error in this story? [email protected] · Instagram
Short link: thejarrus.com/en/microsoft-eviltokens
This story in Turkish: Microsoft, 12 binden fazla gelen kutusunu ele geçiren EvilTokens platformunu çökertti
On the same topic
Robot tests: even the best model completed only 19% of 84 robot tasks, and 63 tasks were solved by no model
In RobotWorld, a benchmark released October 7, the top model, GPT-6 Astra, completed only 16 of 84 simulated robot tasks; no model solved 63 of the tasks.
OpenAI’s image model posts a near-perfect score on text-dense images
On UltraText Bench, a dense-text test led by Westlake University, OpenAI’s GPT Image 2 ranked first of 24 configurations with 99.35 out of 100.
AWS adds Chinese lab Z.ai’s GLM 5.3 model to Amazon Bedrock
AWS added GLM 5.3, a 753-billion-parameter model from Beijing-based Z.ai (formerly Zhipu AI), to Amazon Bedrock for eligible enterprise customers on October 5.