UK cops arrest 2 EvilTokens suspects, Microsoft seizes 50 phishing kit websites
Summary
UK law enforcement has arrested two individuals connected to the EvilTokens phishing-as-a-service. In parallel, Microsoft has seized 50 phishing kit websites that were part of the same operation, which had compromised over 12,000 email inboxes globally.
IFF Assessment
This article details a successful operation by law enforcement and Microsoft against a phishing-as-a-service, but it highlights the significant scale of compromise (12K+ inboxes) and the ongoing threat posed by such operations.
Defender Context
This incident underscores the persistent threat of phishing-as-a-service operations, which equip cybercriminals with sophisticated tools to conduct widespread attacks. Defenders should remain vigilant against phishing attempts, educate users on identifying malicious emails, and implement robust email security solutions to detect and block such threats.