Threat Intelligence

Microsoft Takes Down Major Phishing Service Targeting Microsoft 365 Accounts

Dark Reading · 23 Sept 2026
Key Takeaway Enable multi-factor authentication on all Microsoft 365 accounts and train staff to recognise phishing attempts, since criminal services designed to steal these credentials remain common.

Microsoft has disrupted a phishing-as-a-service operation known as EvilTokens, which was used by cybercriminals to target Microsoft 365 accounts. As part of the coordinated action, the company seized 50 websites and disabled more than 150 domains connected to the platform.

Phishing-as-a-service platforms lower the barrier to entry for cybercrime by providing ready-made tools and infrastructure that criminals can rent to launch attacks, in this case against businesses relying on Microsoft 365 for email and productivity tools. Disrupting the infrastructure behind such services can significantly reduce the volume of related phishing attempts, at least in the short term.

For small businesses using Microsoft 365, this action highlights the ongoing threat of phishing services that specifically target cloud-based business accounts. Even with services like this disrupted, similar platforms are likely to emerge, so maintaining strong account protections remains essential.

Summarised by CISO AI from Dark Reading. We link back to every original so you can read it yourself.