Microsoft · Safety and security · OpenAI
Microsoft dismantled EvilTokens, which had compromised more than 12,000 inboxes
The device-code phishing service, which used AI at every step of the attack chain, was linked to more than 12,000 compromised inboxes across over 10,000 organizations. The operation, authorized by the US District Court for the Eastern District of Virginia, seized 50 sites and took down more than 150 supporting domains, with Cloudflare, Coinbase, OpenAI and others taking part. The service had sold since February for a $1,500 sign-up fee and $500 a month. An AI chatbot read victims’ messages, mapped internal roles and found conversations about payments. London police arrested two men on September 11.
Sources
- Microsoft On the Issues, “Disrupting EvilTokens: The AI Chatbot Built for Cybercrime”, (blogs.microsoft.com)
- Microsoft Security Blog, “Unmasking EvilTokens: Getting to the root of device code phishing”, (microsoft.com)
About this story
This story was posted on Instagram by @jarrus.tech on Sept. 27, 2026.
Spotted an error in this story? [email protected] · Instagram
Short link: thejarrus.com/en/h8-49
This story in Turkish: Microsoft, 12 binden fazla gelen kutusunu ele geçiren EvilTokens platformunu çökertti
On the same topic
OpenAI is rolling out GPT-6 to everyone in ChatGPT
OpenAI began rolling out GPT-6 to everyone in ChatGPT on October 7. Its new Intelligent UI builds answers from text, visuals and interactive elements.
Microsoft opens pre-orders for a $5,999 developer PC that can run 120-billion-parameter models locally
Microsoft opened pre-orders on October 7 for the $5,999 Surface RTX Spark Dev Box, built on Nvidia’s RTX Spark superchip, with shipping starting in November.
OpenAI’s unreleased model wrote 722 math papers
On October 6, OpenAI published 722 math papers from an unreleased internal model on GitHub. It withdrew three on October 7, leaving 719 in the catalog.