In the News · Impersonation Radar

Microsoft disrupts phishing service used for inbox theft

24 September 2026 · Source: finance.yahoo.com

Microsoft said it worked with law enforcement and industry partners to disrupt a cybercrime service called EvilTokens. The operation seized 50 websites and disabled more than 150 related domains. Reports tied the service to more than 12,000 compromised inboxes across 10,000 organizations, with attackers using AI to search stolen email for payment discussions and people to impersonate. This matters because stolen inbox access can quickly lead to invoice fraud, fake payment requests, and business impersonation. A service like Sender Registry helps companies spot risky senders, identify suspicious domains, and reduce the chance that a trusted email account is used as part of a scam.

How Sender Registry helps

Impersonation Radar watches certificate logs for lookalike domains the moment they are registered, so a fake is caught before it is ever used against you.

See how Sender Registry helps →
Read the full story at finance.yahoo.com → ← Back to In the News

Save it before you need it.

Add our reporting address to your contacts now, so it's already there the next time a suspicious email lands in an inbox.

QR code that adds Sender Registry's reporting address to your contacts

Scan with your phone's camera to save straight to your contacts.

Save to your contacts now, so it's already there next time you need it.

Add to Contacts QR code that adds Sender Registry's reporting address to your contacts

Or share this QR code with someone on another device.