HUGE AI-powered Microsoft Account phishing campaign

HUGE AI-powered Microsoft Account phishing campaign

🎙 John Hammond 👥 2.2M 📅 April 9, 2026 ⏱ 15 min 👁 39K 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

device code phishingAI-powered attacksMicrosoft 365Evil TokensRailway

Summary

John Hammond discusses a large-scale phishing campaign targeting Microsoft 365 accounts, leveraging AI and the legitimate device code authentication flow. The campaign, attributed to the ‘Evil Tokens’ phishing-as-a-service platform, uses Railway (a platform-as-a-service) to rapidly deploy personalized phishing lures. These lures, hosted on Cloudflare Workers, mimic legitimate services like DocuSign and Adobe Acrobat, and use redirect services to bypass email security. The video demonstrates live phishing pages, shows the backend of Evil Tokens via Telegram, and highlights the role of AI in generating unique lures for each victim. Hammond emphasizes the collaboration with Flare for threat intelligence and provides mitigation advice. The campaign affected over 340 organizations globally, with no identical lures, showcasing the scalability of AI-driven attacks.

118 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights into a real, ongoing phishing campaign, with concrete examples and technical details. The argumentation is solid, supported by evidence from live phishing pages, the Evil Tokens Telegram channel, and collaboration with Flare. The presenter effectively demonstrates how AI and PaaS are abused for phishing, making a compelling case for the threat’s severity. However, the argumentation relies heavily on anecdotal evidence and the presenter’s own analysis, which may not be fully generalizable.

Scientific Rigor, Source Quality, Title Accuracy

The video demonstrates strong scientific rigor by referencing a detailed blog post from Huntress and collaborating with Flare for threat intelligence. The sources are credible and directly relevant. The title accurately reflects the content, and the video stays on topic. The presenter also mentions that the campaign was covered by The Hacker News, adding external validation. However, the video is primarily an expert opinion and lacks peer-reviewed sources, which slightly reduces its scientific rigor.

165 words

Title / Content Match

The title accurately reflects the content, which details a large-scale AI-powered phishing campaign targeting Microsoft accounts.

Quality & Reliability

8/10

The video is based on real incident analysis by Huntress, with collaboration from Flare, and includes direct evidence from live phishing pages and Telegram channels. The information is technical and specific, but relies heavily on the presenter's expertise and may lack peer-reviewed sources.

Key Moments

Cited Sources

Concurring Sources

  • The Hacker News — Mentioned in the video as covering the campaign, providing external validation.

Contribution & Novelties

The video provides a timely and detailed analysis of a real AI-powered phishing campaign, highlighting the abuse of legitimate services like Railway and Cloudflare Workers. It offers unique insights into the operational aspects of phishing-as-a-service platforms and the role of AI in generating personalized lures. The collaboration with Flare adds valuable threat intelligence data.

Pour aller plus loin :

100 words

Radar Profile

The radar profile shows high scores in information quantity, quality, and reliability, with a slightly lower technical level. This indicates a well-researched and informative video that is accessible to a broad audience, though it may not delve into the most advanced technical details.

Reliability 8/10

💬 No comments were provided for analysis.