AT2k Design BBS Message Area
Casually read the BBS message area using an easy to use interface. Messages are categorized exactly like they are on the BBS. You may post new messages or reply to existing messages!

You are not logged in. Login here for full access privileges.

Previous Message | Next Message | Back to Slashdot  <--  <--- Return to Home Page
   Local Database  Slashdot   [90 / 102] RSS
 From   To   Subject   Date/Time 
Message   VRSS    All   Microsoft Helps Take Down Massive Automated, AI-Powered Phishing   September 23, 2026
 2:20 AM  

Feed: Slashdot
Feed Link: https://slashdot.org/
---

Title: Microsoft Helps Take Down Massive Automated, AI-Powered Phishing-as-a-
Service Platform

Link: https://yro.slashdot.org/story/26/09/23/06212...

Microsoft's security blog describes the fight against a new "AI-powered
cybercrime platform" offering phishing-as-a-service, with AI-tailored lures
and analyses of compromised inboxes (to identify high-value targets). The
site compromised more than 12,000 inboxes in over 10,000 organizations around
the world, compromising business accounts "at scale" with automated attacks
and prebuilt phishing templates. AI tools could even sift through a victim's
mailbox to help engineer better phishing messages. To disrupt EvilTokens
Microsoft worked with other organizations, including Cloudflare, Coinbase,
OpenAI, Railway, SpyCloud, Shadowserver Foundation, and TRM Labs to Health-
ISAC (a non-profit helping health sector organizations share cyber threat
information). "Fifty sites seized and 150 domains disabled in a single action
is only possible when the hosting providers, the exchanges, the model
providers and the data holders all move at the same time," security company
SpyCloud told The Hacker News. From Microsoft's security blog: Microsoft also
notified affected customers, helped remediate compromised accounts, and
shared intelligence to support further defensive and investigative action...
Microsoft worked closely with specialist officers from the Metropolitan
Police Service's cybercrime team, sharing intelligence that enabled officers
to take operational action in the United Kingdom. On September 11, 2026,
officers arrested two men, aged 32 and 38, and seized digital devices and
other items for examination... While EvilTokens used AI to identify targets
and prioritize fraud opportunities, Microsoft investigators used reverse
engineering and AI-powered tools to analyze evidence, accelerate the
investigation, and identify the infrastructure supporting the service...
Campaigns leveraging EvilTokens have impacted organizations in various
industries, including wholesale distribution, construction, financial
services, real estate, higher education, and healthcare, with the highest
concentrations of observed victim activity in the United States, Canada, the
United Kingdom, Australia, India, and France. Working with partners,
Microsoft's Digital Crimes Unit (DCU) facilitated a coordinated disruption of
infrastructure used to operate the EvilTokens service. Sometimes stolen
tokens were used to give new devices access to a victim's inbox. (A code
authenticating the new device was sent to the targeted user, who unknowingly
authorize the threat actor's session and grants access to their account...)
But "AI was not simply helping attackers write more convincing messages,"
says another Microsoft blog post. "It helped them decide who to target, who
to impersonate, and how to most effectively exploit the relationship to
extract as much money as possible." The significance of EvilTokens extends
beyond its rapid growth and global reach. It offers an early warning of what
happens when cybercriminals combine stolen access with AI capable of
understanding how an organization works... Its AI tools could summarize and
translate emails, surface financial conversations, map organizational roles,
identify trusted relationships, and recommend potential targets. Preset
prompts offered to find wire-transfer discussions, identify the
organization's "money movers," locate vendor invoices, and determine the best
people to impersonate. Sold through Telegram for a $1,500 initiation fee and
a recurring $500 subscription, EvilTokens combined account compromise,
mailbox analysis, target selection, and fraud preparation in a single
service. Capabilities that once required experience across identity attacks,
cloud systems, social engineering, and financial fraud were available through
a ready-made interface. Investigators found evidence that large portions of
EvilTokens had been "vibe coded," with AI helping its creators build the
platform itself. They also determined that EvilTokens drew on capabilities
from multiple AI models. The result was more than a collection of attack
tools. EvilTokens packaged much of the fraud process into a commercially run
service, complete with subscription pricing, customer support, management
dashboards, and tools designed to move customers from account access toward
financial exploitation.

Read more of this story at Slashdot.

---
VRSS v2.1.180528
  Show ANSI Codes | Hide BBCodes | Show Color Codes | Hide Encoding | Hide HTML Tags | Show Routing
Previous Message | Next Message | Back to Slashdot  <--  <--- Return to Home Page

VADV-PHP
Execution Time: 0.0154 seconds

If you experience any problems with this website or need help, contact the webmaster.
VADV-PHP Copyright © 2002-2026 Steve Winn, Aspect Technologies. All Rights Reserved.
Virtual Advanced Copyright © 1995-1997 Roland De Graaf.
v2.1.250224