Unmasking EvilTokens: Getting to the root of device code phishing
Factual evidence
What the source reports
Microsoft DCU and partners disrupted EvilTokens, a PhaaS platform that used AI-assisted lures to execute device code phishing attacks.
Inspect the evidence
- Inclusion basis
- Enterprise AI
- Publisher and source type
- Microsoft Security Blog · ENTERPRISE AI
- Published by source
- 22 September 2026
- Collected by OneBench
- 23 Sept 2026, 09:01 UK
- Original headline
- Unmasking EvilTokens: Getting to the root of device code phishing ↗
Stored source excerpt
EvilTokens has quickly become one of the top PhaaS platforms, enabling device code phishing attacks through AI-assisted lures, automated infrastructure, and token theft. In collaboration…
Short excerpt from the collected text, not the full source. Use the source link to read it in context.
The factual summary is a OneBench synthesis, not a quotation or independent verification. Collection time is not publication time. Open the source for its full context; related reporting can share the same underlying announcement.
OneBench interpretation
Institutional assessment
So what
AI-driven PhaaS platforms target enterprise single sign-on workflows, increasing risk to financial identity infrastructure.
Do what
Review device code authentication policies and phishing controls with the team responsible for identity and access management.