Cloudflare, Microsoft dismantle AI-powered MFA phishing ring targeting Australia

Cloudflare and Microsoft say they have taken part in a coordinated effort with law enforcement partners to disrupt “EvilTokens”, a phishing-as-a-service operation designed to bypass multi-factor authentication (MFA) and fa

Cloudflare, Microsoft dismantle AI-powered MFA phishing ring targeting Australia

Cloudflare, Microsoft dismantle AI-powered MFA phishing ring targeting Australia


Cloudflare and Microsoft say they have taken part in a coordinated effort with law enforcement partners to disrupt “EvilTokens”, a phishing-as-a-service operation designed to bypass multi-factor authentication (MFA) and facilitate business email compromise (BEC).

According to Cloudflare’s threat intelligence team, Cloudforce One, Australia was among the countries with the highest concentration of victim activity linked to the service. The companies said the platform was associated with more than 12,000 compromised inboxes across more than 10,000 organisations globally.

EvilTokens first emerged on Telegram in January 2026, Cloudflare said, and was built to automate the collection of Microsoft Office 365 authentication tokens. Cloudflare said the toolset was also designed to maintain access after session tokens expired, increasing the risk that victims could remain compromised even after changing passwords or re-authenticating.

Cloudflare said the operation also incorporated an “AI coach” intended to help users craft phishing lures, including guidance related to US tax documents and common invoice and accounting formats. The inclusion of AI-enabled prompts is likely to further lower the barrier to entry for less experienced criminals, increasing the scale and speed at which credential theft and BEC campaigns can be launched.

As part of the disruption, Microsoft’s Digital Crimes Unit initiated a civil legal action in the United States to seize control of domains linked to the operation, Cloudflare said. Cloudflare said it carried out a technical sweep that blocked hundreds of domains and disabled malicious Cloudflare Worker scripts used in the campaign.

About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.