Security News

Cloudflare and Microsoft Take Down AI-Powered Phishing Service Targeting Australian Businesses

Key Takeaway Because this attack can survive password resets by stealing active login sessions, Australian businesses should ensure staff report suspicious login prompts immediately and enable session monitoring or conditional access alerts on Microsoft 365 accounts.

Cloudflare and Microsoft, working with law enforcement, have disrupted a phishing-as-a-service operation called 'EvilTokens' that was designed to bypass multi-factor authentication (MFA) and enable business email compromise (BEC) scams. Cloudflare's threat intelligence team said Australia had one of the highest concentrations of victims worldwide, with the service linked to more than 12,000 compromised inboxes across over 10,000 organisations.

The service, which first appeared on Telegram in January 2026, automated the theft of Microsoft Office 365 login tokens and was built to keep attackers inside compromised accounts even after victims changed their passwords or logged in again. It also included an 'AI coach' feature that helped criminals write convincing phishing emails, including lures disguised as tax documents and invoices, making it easier for less skilled attackers to run large-scale scams.

To shut the operation down, Microsoft's Digital Crimes Unit launched a civil legal action in the United States to seize control of domains used by the service, while Cloudflare blocked hundreds of related domains and disabled malicious scripts hosted on its network.

phishing MFA bypass business email compromise

Summarised by CISO AI from Australian Cyber Security Magazine. We link back to every original so you can read it yourself.