EvilTokens takedown cuts access to 12,000 compromised inboxes

EvilTokens takedown cuts access to 12,000 compromised inboxes. Thousands of organizations gained some protection after the EvilTokens phishing service was disrupted.

This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Monday, September 28th, 2026.

Thousands of organizations gained some protection after the EvilTokens phishing service was disrupted. The service had compromised more than twelve thousand inboxes across over ten thousand organizations. Microsoft led a coalition of law enforcement and private-sector partners in the takedown. Even so, disrupting the service doesn’t resolve the exposure of every affected inbox.

A compromised mailbox can reveal sensitive conversations and give criminals a trusted channel for additional fraud. The scale here also shows how one phishing service can spread risk across a large number of organizations.

For leaders, the takedown is valuable, but affected accounts still need an internal response. For defenders, that means reviewing suspicious sign-ins, revoking active sessions, resetting exposed credentials, and examining mailbox rules for unauthorized changes. Identity recovery has to continue even after criminal infrastructure goes offline. Treat every identified EvilTokens account as compromised and complete a full identity and mailbox reset.

For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.

EvilTokens takedown cuts access to 12,000 compromised inboxes
Broadcast by