Microsoft and Law Enforcement Disrupt EvilTokens Phishing Platform Following Mass Account Compromise
AI-generated from multiple sources. Verify before acting on this reporting.
LONDON — Microsoft coordinated a global operation on Monday to disrupt EvilTokens, a phishing-as-a-service platform that compromised more than 12,000 accounts across over 10,000 organizations worldwide. The takedown was executed in collaboration with the company's Digital Crimes Unit, the Health-ISAC, international law enforcement agencies, and cybersecurity firm SpyCloud.
The operation targeted the threat actor known as Storm-2992, who operated the EvilTokens infrastructure to facilitate business email compromise campaigns. Authorities arrested suspects at locations in Canary Wharf and Nine Elms in London, marking a significant development in the case. The platform had been active for months, utilizing device-code phishing techniques to trick users into surrendering credentials, which attackers then used to infiltrate corporate Microsoft environments.
Microsoft's Digital Crimes Unit identified the scale of the breach after detecting anomalous login patterns consistent with the EvilTokens methodology. The compromised accounts spanned various sectors globally, allowing threat actors to access sensitive communications and financial data within targeted organizations. The Health-ISAC played a critical role in alerting healthcare entities about the specific risks posed by the campaign, enabling rapid defensive measures before further damage occurred.
The disruption of the EvilTokens platform effectively halted the active distribution of phishing kits and severed the command-and-control channels used by Storm-2992. However, cybersecurity experts warn that the initial compromise of over 12,000 accounts leaves many organizations vulnerable to residual threats. Attackers who obtained credentials prior to the takedown may still possess valid access tokens or have exfiltrated data before the infrastructure was dismantled.
Law enforcement officials stated that the arrests in London are part of a broader investigation into the financial networks supporting the operation. While the immediate threat of the EvilTokens platform has been neutralized, investigators are working to trace the full extent of the data stolen during the campaign. The Health-ISAC continues to monitor for any resurgence of similar phishing tactics as other criminal groups attempt to fill the void left by Storm-2992.
Questions remain regarding the total financial impact on the affected organizations and whether all compromised credentials have been successfully rotated. Microsoft has advised enterprises to review their authentication logs and enforce multi-factor authentication protocols immediately. As the investigation into the arrested suspects proceeds, authorities expect to uncover additional details about the scope of the operation and potential links to other criminal networks. The case underscores the evolving nature of phishing-as-a-service models and the increasing sophistication of cybercriminal infrastructure targeting global enterprises.