PrivacySignal
Breach

EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts

BleepingComputer · · International · Data Breaches

The EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft's Digital Crimes Unit (DCU). [...]

Who should care: Cybersecurity · Privacy officers · Administrators

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

The Attacker Did Not Need to Sleep

Spain received its first reported personal-data breach carried out by an AI agent. The techniques were familiar. The speed and autonomy were not.

· 4 min read Read →

Related stories

Breach
The Record · · International

Two arrested in UK after Microsoft takedown of ‘Eviltokens’ AI-chatbot for cybercriminals

UK authorities arrested two people following a Microsoft-led takedown of EvilTokens, a subscription-based AI service sold on Telegram that helped cybercriminals break into accounts, sift through stolen email data, and find ways to profit from the access.

Who should care: Cybersecurity · Privacy officers · Administrators · AI governance · Lawyers · General readers · Policy

#breach#ai-governance#ai Read original →
Breach
CyberScoop · · US Federal

Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud

The popular phishing-as-a-service platform used AI throughout the attack chain, allowing cybercriminals to steal tokens for account takeover and business email compromise. The post Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud appeared first on CyberScoop.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai#security Read original →
Breach
HIPAA Journal · · US Federal

Call-on-Doc Notifies Patients About December 2025 Hacking Incident

Call-on-Doc, a telemedicine platform, has notified patients of a cyberattack and data breach that occurred in December 2025. The company disclosed the incident in line with breach notification requirements.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
HIPAA Journal · · US Federal

Albany College of Pharmacy and Health Sciences Data Breach Settlement

Albany College of Pharmacy and Health Sciences has agreed to settle a class action lawsuit related to a data breach at the New York institution. The settlement follows legal action brought against the college over the incident.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals

#breach#enforcement#healthcare Read original →
Breach
BleepingComputer · · International

BigCommerce alerts merchants of data breach linked to Ribon apps

Ecommerce platform BigCommerce has alerted multiple merchants to data breaches after attackers compromised credentials for third-party Ribon applications and used them to inject malicious scripts into online stores. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
HIPAA Journal · · US Federal

Data Breach at Translation Vendor Affects UnitedHealthcare Plan Members

United Language Group, a translation services vendor in Minnesota, has disclosed a data breach affecting members of UnitedHealthcare health plans. Two other healthcare providers, Desert Pulmonary & Sleep Consultants in Arizona and Azle, also announced separate breaches.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →