Cybersecurity News in Asia

RECENT STORIES:

SEGA moves faster with flow-based network monitoring
EvilTokens takedown leaves compromised accounts unresolved
Why Businesses Need to Treat AI Agents Like Privileged Insiders
Kaspersky and Best Telecom expand strategic cooperation to strengthen ...
Autonomous agents flood UN website with thousands of data requests
Emergency updates fix CoreGraphics zero day linked to targeted zero cl...
LOGIN REGISTER
CybersecAsia
  • Features
    • Featured

      Why Businesses Need to Treat AI Agents Like Privileged Insiders

      Why Businesses Need to Treat AI Agents Like Privileged Insiders

      Thursday, October 1, 2026, 10:00 AM Asia/Singapore | Expert Opinion, Features, Sponsored
    • Featured

      Shadow AI Is the New Insider Threat

      Shadow AI Is the New Insider Threat

      Monday, September 21, 2026, 9:11 AM Asia/Singapore | Features, Newsletter, Sponsored, Tips
    • Featured

      Addressing the AI-driven vulnerability debt

      Addressing the AI-driven vulnerability debt

      Thursday, September 17, 2026, 10:03 AM Asia/Singapore | Features, Sponsored
  • Opinions
  • Tips
  • Whitepapers
  • AWARDS 2026
  • Directory
  • E-Learning

Select Page

News

EvilTokens takedown leaves compromised accounts unresolved

By CybersecAsia Editors | Friday, October 2, 2026, 9:37 AM Asia/Singapore

EvilTokens takedown leaves compromised accounts unresolved

The latest disruption disables websites and domains, but unauthorized sessions may persist; investigators have not published how many victims were remediated

Blocking the websites and scripts behind a phishing service can prevent victims from reaching its traps. However, this does not automatically eject attackers from email accounts they have already entered.

That distinction matters — after the September 2026 disruption of EvilTokens, a service used to obtain access to Microsoft 365 inboxes.

The attackers did not need to steal passwords. Their phishing pages gave victims a code to enter on a legitimate sign-in page. Completing the sign-in authorised an attacker-controlled session, potentially including access and refresh tokens. A password reset alone may not end that access if the sessions and tokens remain valid.

Also, the phishing service’s delivery infrastructure extended beyond any one set of domains. In March 2026, researchers had traced EvilTokens-linked campaigns through compromised websites, online services and short-lived phishing pages hosted on a serverless platform. They reported the pages they observed to the host and said most, if not all, had already been removed. However, that earlier action did not end the campaigns, according one report. The September intervention went further…

Taking civil action against phishing syndicates

A US civil action has enabled the seizure of 50 websites used to operate EvilTokens, and the disabling of more than 150 supporting domains, according to plaintiffs, Microsoft and Health-ISAC.

A hosting provider had testified that it had banned hundreds of associated domains and serverless projects, and put warning pages in front of some phishing links it could not seize.

Another entity, Cloudflare, has testified that it has taken action against domains and phishing pages and scripts hosted on its serverless computing platform.

Nevertheless, published figures describing how the syndicate infrastructure has been affected, could not tally the number of campaigns stopped or accounts secured.

An unanswered question

For organisations investigating exposure, the relevant question is whether employees completed the device-code sign-in and whether unauthorised sessions remain active.

The infrastructure takedown cannot answer either question for an individual account. There is also no public evidence yet that EvilTokens cannot resume operations using replacement infrastructure.

Microsoft has notified affected customers and helped remediate compromised accounts; it has not published a count of accounts remediated.

For now, the UK police has arrested two men in a related investigation in early September 2026. Both were released on bail while inquiries continue.

Share:

PreviousWhy Businesses Need to Treat AI Agents Like Privileged Insiders

Related Posts

Cybercriminals take quishing to new heights with split/nested malicious QR codes

Cybercriminals take quishing to new heights with split/nested malicious QR codes

Wednesday, August 27, 2025

Experts warn of Iranian cyber retaliation after massive US-Israeli digital offensive

Experts warn of Iranian cyber retaliation after massive US-Israeli digital offensive

Thursday, March 5, 2026

The expanding corporate perimeter calls for more than just NGAV

The expanding corporate perimeter calls for more than just NGAV

Monday, August 23, 2021

Stopping COVID-19 – and fake news – without vaccines

Stopping COVID-19 – and fake news – without vaccines

Monday, April 13, 2020

Leave a reply Cancel reply

You must be logged in to post a comment.

Voters-draw/RCA-Sponsors

Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
previous arrow
next arrow

CybersecAsia Voting Placement

Gamification listing or Participate Now

LEARN MORE

Vote Now -Placement(Google Ads)

Top-Sidebar-banner

Whitepapers

  • Critical Security Threatsand the Need for ZTNA: How evolving cyberattacks demand a Zero Trust approach

    Critical Security Threatsand the Need for ZTNA: How evolving cyberattacks demand a Zero Trust approach

    Cyber threats have become more frequent and sophisticated, targeting organizations of all sizes across all …Download Whitepaper
  • Zero Trust Made Simple: Why it matters and how to get started

    Zero Trust Made Simple: Why it matters and how to get started

    Data breaches and cyberattacks are no longer limited to large, high-profile organizations.Download Whitepaper
  • Cloud Secure Edge: Remote access, better security

    Cloud Secure Edge: Remote access, better security

    ​SonicWall Cloud Secure Edge™ is a modern, cloud-native Security Service Edge (SSE) solution that addresses …Download Whitepaper
  • Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Insider threats continue to be a major cybersecurity risk in 2024. Explore more insights on …Download Whitepaper

Middle-sidebar-banner

Case Studies

  • How a Vietnamese D2C retailer built its own secure digital infrastructure

    How a Vietnamese D2C retailer built its own secure digital infrastructure

    Would your organization build your own digital infrastructure – including AI governance and cybersecurity – …Read more
  • Cyber protection for medical clinics in Singapore

    Cyber protection for medical clinics in Singapore

    As Singapore’s healthcare sector becomes increasingly digital and interconnected, clinics are facing heightened cyber risks, …Read more
  • India’s WazirX strengthens governance and digital asset security

    India’s WazirX strengthens governance and digital asset security

    Revamping its custody infrastructure using multi‑party computation tools has improved operational resilience and institutional‑grade safeguardsRead more
  • Bangladesh LGED modernizes communication while addressing data security concerns

    Bangladesh LGED modernizes communication while addressing data security concerns

    To meet emerging data localization/privacy regulations, the government engineering agency deploys a secure, unified digital …Read more

Bottom sidebar

Other News

  • Kaspersky and Best Telecom expand strategic cooperation to strengthen digital security in Laos

    Wednesday, September 30, 2026
    VIENTIANE, Laos, Sept. 30, 2026 …Read More »
  • SU Group Narrows First-Half Operating Loss, Executes on Long-Term Strategy

    Wednesday, September 30, 2026
    Business Momentum Led by Public-Sector …Read More »
  • Hikvision introduces new HIKO AI engine to Hik-Connect 7 in a major upgrade which simplifies day-to-day security management

    Tuesday, September 29, 2026
    HANGZHOU, China, Sept. 29, 2026 …Read More »
  • Taoping Reports First Half 2026 Results

    Tuesday, September 29, 2026
    Gross Margin Expands 270 Basis …Read More »
  • Inspira Enterprise Named Major Contender in Everest Group’s 2026 Cybersecurity Services PEAK Matrix®

    Tuesday, September 29, 2026
    MUMBAI, India, RIYADH, Saudi Arabia, …Read More »
  • Our Brands
  • DigiconAsia
  • MartechAsia
  • Home
  • About Us
  • Contact Us
  • Sitemap
  • Privacy & Cookies
  • Terms of Use
  • Advertising & Reprint Policy
  • Media Kit
  • Subscribe
  • Manage Subscriptions
  • Newsletter

Copyright © 2026 CybersecAsia All Rights Reserved.