Attackers don't need a password: dangerous phishing attacks use real Microsoft logins
⚡ Quick Summary
An extremely sophisticated phishing campaign is currently spreading through a criminal service called “EvilTokens” that targets Microsoft 365 accounts. The attackers do not need a password.