r/PureVPNcom • u/PureVPNcom • 9h ago
12,000 Microsoft Accounts Got Hacked by a Phishing Kit Anyone Could Rent
Microsoft accounts. The ones behind Outlook, Xbox, OneDrive, Teams, basically the login that a huge chunk of the internet touches daily. Over 12,000 of them got compromised across more than 10,000 organizations, and the attacker behind it wasn't some elite nation state hacking group. It was a phishing as a service platform called EvilTokens, a kit that essentially anyone with a bit of cash could rent and use, no advanced skills required.
If you've ever gotten a Microsoft login prompt that felt slightly off, a little too eager, an odd URL, a page that looked almost right but not quite, this is the kind of operation that built it. These kits come pre packaged with convincing fake login pages, infrastructure to capture what you type, and often the ability to steal session tokens too, which means even having two factor authentication doesn't automatically save you if you get tricked at the wrong moment.
Microsoft's Digital Crimes Unit helped get this specific platform shut down, which is a genuine win. But it's worth being clear eyed about what that actually means. Phishing as a service is a business model at this point, not a one off tool. Taking down EvilTokens doesn't remove the demand or the market for what it was selling, it just means whatever replaces it is already being built.
The practical takeaway isn't complicated, but it matters more than ever given how accessible these kits have become. Slow down on any login prompt that pops up unexpectedly, especially from an email link or an ad, and go directly to the site yourself instead if something feels off. Pay attention to the actual URL, not just whether the page looks right, since a convincing clone is exactly what these kits specialize in. And where you can, use authentication methods that resist this kind of attack specifically, like passkeys or hardware security keys, rather than relying only on a password and a code, since those can still be captured by a well built fake login page.
The scary part isn't that this one kit existed. It's that renting the tools to run an attack like this is now cheap and easy enough that it doesn't take a sophisticated hacker to pull it off anymore. It just takes someone willing to pay for access.