Field Analysis
EvilTokens Goes Down: What a PhaaS Takedown Actually Buys You
Microsoft's DCU disrupted EvilTokens on September 22, 2026 — a $1,500 device-code phishing platform tied to 12,000 compromised inboxes across 10,000 organisations. The operator is gone. The flow it abused is unchanged, and the serverless infrastructure pattern is the part that outlives the brand.
Read more:Microsoft Security BlogThe Hacker News