Breach Watch, September 22, 2026: Microsoft Disrupts an AI-Powered Phishing Service That Hit 12,000 Accounts
CISO PLATFORM · BREACH INTELLIGENCE
BREACH WATCH
Daily Breach Intelligence for Security Leaders · September 22, 2026

TL;DR for CISOs: Microsoft and a coalition of partners dismantled EvilTokens, an AI-assisted phishing-as-a-service platform that compromised more than 12,000 inboxes at over 10,000 organizations, and two suspected administrators were arrested in London. Separately, the ShinyHunters extortion group claims it breached FBI systems through a new, unverified Oracle PeopleSoft zero-day and stole 2 to 3 terabytes of employee and applicant data; the FBI says it is investigating but has not confirmed the claim. And in a single day, CISA added four critical, actively exploited vulnerabilities to its catalog spanning F5, Check Point and Arista network infrastructure.

BOTTOM LINE FOR CISOS
  1. Device-code phishing paired with AI-assisted target selection is now sold as a commercial subscription service, complete with support and dashboards. Disabling device-code authentication where it is not genuinely needed is one of the few controls that closes this off entirely, and it costs nothing to turn off.
  2. An unverified claim is still a signal. Whatever the truth of the FBI allegation turns out to be, ShinyHunters has a track record of surfacing real Oracle zero-days before they were publicly confirmed. If your organization runs PeopleSoft, especially internet-facing HR or recruiting modules, this is the week to ask Oracle directly rather than wait for a CVE.
  3. Four critical, actively exploited flaws landed in CISA's catalog in a single day across three network and access-management vendors. Two of them were exploited in the wild for weeks before anyone noticed. A patch date on your ticket is not proof that attackers didn't get there first; verify, don't just close the ticket.

Lead story: Microsoft dismantles an AI-powered phishing service that hit 12,000 accounts

HIGH · CRIMINAL SERVICE DISRUPTED
Key facts
Platform: EvilTokens, a phishing-as-a-service (PhaaS) operation Microsoft tracks as Storm-2992, active since February 2026
Scale (Microsoft): more than 12,000 Microsoft inboxes compromised across over 10,000 organizations worldwide
Scale (SpyCloud): 8,708 compromised accounts recaptured across 6,585 corporate domains in 79 countries, about 97.5% enterprise
Sectors hit: wholesale distribution, construction, financial services, real estate, higher education, healthcare
Technique: device-code phishing, abusing Microsoft's legitimate OAuth 2.0 device-authorization flow to obtain tokens without credential theft
Pricing: $500 a month or a $1,500 one-time fee via Telegram, with 44 customizable phishing kits and paid add-ons
Disruption: Microsoft's Digital Crimes Unit with Health-ISAC, law enforcement and SpyCloud obtained legal authority to seize infrastructure
Arrests: two men, aged 32 and 38, arrested in London on September 19 by the Metropolitan Police, released on bail pending investigation

What happened

EvilTokens was the first phishing-as-a-service platform to support device-code authentication at scale, and it built a genuine business around the technique: subscription pricing, customer support, management dashboards, 44 customizable phishing kits, and paid add-ons for anti-bot redirectors and bulk email sending. Lures impersonated document-signing platforms, Microsoft services, cloud file-sharing providers, invoicing systems and eFax services, with subjects ranging from construction bids and partnership agreements to password-expiration warnings.

The technique itself abuses a legitimate Microsoft feature. OAuth 2.0's device-authorization flow exists for devices with limited input, such as smart TVs, printers and some Teams conferencing hardware. An attacker starts a device-code request and sends the resulting code to a target inside a phishing lure. The victim is directed to Microsoft's own legitimate login portal, enters the code, and authenticates, handing the attacker a valid token without ever typing a password an attacker could steal directly, and without necessarily triggering multi-factor prompts the way credential theft would.

Once inside a mailbox, EvilTokens used Microsoft Graph to map organizational relationships and AI-powered tools to read mailbox content and identify high-value targets, then generated contextually relevant business email compromise messages, searching specifically for wire-transfer information, pending invoices and executive correspondence. To evade detection, the platform used multi-stage redirects, PDF and HTML attachments, fake CAPTCHA pages, and traffic routed through legitimate cloud platforms including Vercel, Cloudflare Workers and AWS Lambda.

Microsoft, working with Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, the Shadowserver Foundation and TRM Labs, obtained legal authority from the US District Court for the Eastern District of Virginia to seize the service's active infrastructure. The UK's Metropolitan Police Service received information about two suspected administrators in August and executed warrants on September 19 at addresses in Canary Wharf and Nine Elms, arresting a 32-year-old and a 38-year-old man, both released on bail pending further investigation. Microsoft is explicit that this was a disruption, not a full takedown: the threat remains active, though attack volume should decrease noticeably, and affiliates have already built clones such as APToken based on the same toolkit.

Evidence

Verified against two independent sources:
1. Microsoft Security Blog, "Unmasking EvilTokens: Getting to the root of device code phishing," September 22, 2026
2. BleepingComputer, "EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts," September 22, 2026

What this means for your team

The barrier to running a sophisticated BEC operation is now a $500 monthly subscription. EvilTokens packaged reconnaissance, lure generation and target prioritization into a managed service with customer support, which means the skill and infrastructure an attacker needs has collapsed to whatever a Telegram payment can buy. Assume every mid-size criminal crew you might worry about already has access to tooling this capable.

Device-code authentication exists for a narrow set of legitimate use cases that most organizations rarely need on user accounts. If your tenant allows it broadly, you are carrying the exposure of an entire attack category to support a feature few of your employees actually use. This is one of the rare cases in security where the fix is a configuration change with close to zero business cost.

The AI-assisted triage step compresses your response window. Once a mailbox is compromised, the platform can identify wire-transfer conversations and executive correspondence in minutes rather than the hours or days a human operator would need. If your detection depends on an analyst noticing unusual mailbox activity before a fraudulent wire goes out, that race is now harder to win than it was a year ago.

Action checklist
  1. Disable device-code authentication tenant-wide unless a specific, named device genuinely requires it, and block the device-code flow through Conditional Access for everyone else.
  2. Tell your workforce, in plain language, to check the application name shown on Microsoft's own sign-in page before entering any device code, and to never enter a code they did not personally request.
  3. Hunt your Entra ID sign-in logs for device-code grants from unfamiliar devices, locations or applications, and set an alert for any spike in device-code flow usage across the tenant.
  4. If you find a mailbox compromised through this technique, assume BEC targeting already occurred and review wire-transfer, invoice and payment-change requests sent from or to that mailbox in the surrounding 72 hours.

ShinyHunters claims it breached the FBI through a new Oracle PeopleSoft zero-day

HIGH · UNVERIFIED CLAIM
Key facts
Claim source: ShinyHunters extortion group, via its dark web leak site and statements to BleepingComputer and 404 Media
Alleged vector: a new, unpatched Oracle PeopleSoft remote code execution zero-day, allegedly used the night of September 21
Alleged lateral movement: into FBI-managed AWS GovCloud infrastructure, plus FBI Criminal Justice, HR and Medlink services
Alleged volume: 2 to 3 terabytes of data on current and former FBI employees and job applicants
Defacement: the FBI's apply.fbijobs.gov site was defaced, then showed a maintenance message
Independent check: 404 Media verified some details in a roughly 5,000-record sample, including phone numbers matching Department of Justice personnel
FBI statement: "aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating"; has not confirmed a breach or data theft
Alleged motive: retaliation for a May 2026 FBI FLASH report on ShinyHunters, with a seven-day demand to correct or remove it

What happened

ShinyHunters told BleepingComputer it accessed FBI systems through a previously unknown Oracle PeopleSoft remote code execution vulnerability, using it the night of September 21 before moving laterally into FBI-managed AWS GovCloud infrastructure. The group claims it took between 2 and 3 terabytes of data, including records on current and former employees and job applicants, and that it also reached the FBI's Criminal Justice, HR and Medlink services. The group says the FBI detected the intrusion quickly, took the affected systems offline, and cut off access to multiple networks at once.

The FBI's job-applicant site, apply.fbijobs.gov, was defaced with a message reading, in part, that the site had been "seized" and that FBI employee and applicant data had been compromised. The site later displayed a maintenance notice. ShinyHunters shared two sample records with BleepingComputer, including one it said belonged to FBI Director Kash Patel; BleepingComputer is not publishing personal information from those records and has not verified their authenticity. Independent outlet 404 Media, which first reported the story after receiving a separate sample of roughly 5,000 purported employee records, said it verified that some information in the sample was accurate, including phone numbers that corresponded to Department of Justice personnel.

The FBI told BleepingComputer only that it is "aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating," without confirming that its systems were breached or that data was stolen. BleepingComputer says it has not independently verified the alleged zero-day, the lateral movement, or the amount of data taken, and has contacted Oracle and Google Cloud's Mandiant threat intelligence team for comment. ShinyHunters separately claims it is now using the same alleged vulnerability against Fortune 500 companies after previously targeting the education sector. The group has a documented history with Oracle zero-days: it was part of the "Scattered Lapsus$ Hunters" collective that leaked a proof-of-concept for the Oracle E-Business Suite flaw Clop exploited in 2025, a flaw Oracle later confirmed matched the one used in those attacks.

Evidence

Verified against two independent sources:
1. BleepingComputer, "ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach," September 22, 2026
2. TechCrunch, "Hacking group ShinyHunters claims it breached the FBI, stole agents' and applicants' data," September 22, 2026

What this means for your team

Treat this as unresolved, not disproven. Neither the FBI, Oracle nor AWS has confirmed any part of this claim as of this writing, and the details attributed to the attackers should be read as allegations. But this exact group has a track record of surfacing real Oracle zero-days before they were confirmed: the 2025 Oracle E-Business Suite exploit followed a similar pattern of claim, denial, and eventual confirmation weeks later. If you run Oracle PeopleSoft, especially an internet-facing HR or recruiting module, this is a reason to ask your Oracle account team directly this week rather than wait for a public advisory.

The counterintelligence angle is worth naming even while the claim is unverified. If personal data on law enforcement personnel and their families were exposed, the risk model is different from a typical consumer breach: coercion and extortion of employees through their families is a documented tactic against intelligence and law enforcement personnel specifically. Any organization holding data on people whose identity carries operational risk, not just financial risk, should have a distinct playbook for this scenario already written down rather than improvised after the fact.

Action checklist
  1. If you run Oracle PeopleSoft, and especially an internet-facing HR or recruiting portal, contact your Oracle account team directly this week to ask about a possible new remote code execution zero-day rather than waiting for a CVE.
  2. Increase logging and monitoring on any PeopleSoft deployment now, and review recent authentication and administrative activity for anomalies.
  3. Review, or write, an incident response playbook specifically for exposure of personnel data that carries counterintelligence or extortion risk, distinct from your standard consumer-breach notification process.
  4. Track this story for confirmation or retraction over the coming days rather than treating the current lack of confirmation from the FBI and Oracle as the end of the matter.

Same day, four critical zero-days join CISA's exploited list: F5, Check Point and Arista

CRITICAL · ACTIVELY EXPLOITED
Key facts
CVE-2026-94127: F5 BIG-IP Access Policy Manager, CVSS 9.8, unauthenticated remote code execution when APM is configured as an OAuth Authorization Server
CVE-2026-93616: Check Point Management Server family, CVSS 9.8, unauthenticated directory traversal and arbitrary script upload; "a handful of customers" already attacked
CVE-2026-85102: Check Point Security Gateway and Spark Firewall, CVSS 9.8, certificate validation flaw allowing auth bypass; patched September 9, now confirmed under active exploitation globally
CVE-2026-93952: Arista VeloCloud Orchestrator (on-premises), CVSS 10.0, unauthenticated privilege of internal functions on certificate-authenticated deployments
Common thread: all four added to CISA's Known Exploited Vulnerabilities catalog on September 22, federal agencies given three days to patch under BOD 26-04
Patch status: F5 and Check Point Management Server have hotfixes; Arista fixes exist for the 5.2 and 6.4 release trains but not yet for 6.1 or 7.0

What happened

F5 and CISA disclosed on September 22 that attackers have been exploiting CVE-2026-94127, a critical BIG-IP Access Policy Manager flaw, as a zero-day. F5 says it discovered the issue internally; the bug is exploitable only when APM is configured as an OAuth Authorization Server with an access policy on a virtual server, and F5 notes it as a data-plane issue, meaning restricting access to the administrative interface alone does not protect against it. Hotfixes are available for the affected 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3 releases.

The same day, Check Point announced urgent patches for CVE-2026-93616, a directory traversal and file upload flaw in its Management Server, Multi-Domain Management Server, Log Server, Multi-Domain Log Server and SmartEvent products, exploited in the wild against a handful of customers. Check Point's hotfix requires the R82.20 Security Hotfix or the relevant jumbo hotfix accumulator; the company specifically notes that standard LivePatch updates do not resolve it. In the same advisory, CISA added a second Check Point flaw, CVE-2026-85102, a certificate-validation bug in Security Gateway and Spark Firewall products that Check Point patched on September 9 with no evidence of exploitation at the time. Check Point now says it is observing active exploitation attempts against Spark customers globally, meaning the gap between patch availability and confirmed attacker interest was roughly two weeks.

Separately, Arista disclosed that attackers are exploiting CVE-2026-93952 in its on-premises VeloCloud Orchestrator, the server that manages Edge devices in a VeloCloud SD-WAN deployment. The flaw carries a CVSS score of 10.0 and is exposed only on orchestrators where Edges authenticate using certificates rather than a pre-shared key. Arista says the flaw "was discovered externally and is known to be actively exploited" but has not disclosed when the attacks began or how widespread they are. Fixed releases are available for the 5.2 and 6.4 trains; the 6.1 and 7.0 trains do not yet have a fix. All four vulnerabilities were added to CISA's Known Exploited Vulnerabilities catalog on September 22, triggering a three-day federal patch deadline under Binding Operational Directive 26-04.

Evidence

Verified against independently fetched sources:
1. SecurityWeek, "Critical F5 BIG-IP Vulnerability Exploited as Zero-Day," September 23, 2026
2. SecurityWeek, "Check Point Patches Exploited Management Server Zero-Day," September 23, 2026
3. The Hacker News, "New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups," September 22, 2026

What this means for your team

Perimeter and access-management appliances, not endpoints, were the coordinated target class this week. VPN gateways, management consoles and SD-WAN orchestrators sit at the center of how your network is administered, and a single flaw in one of them can be worth more to an attacker than dozens of endpoint compromises. If your patch cadence treats appliance vendors as lower priority than desktop software, this is the week that assumption gets tested.

The Check Point Spark timeline is the detail to sit with. A flaw patched September 9 with no evidence of exploitation was, by September 22, under active attack globally. Two weeks of "patched and closed" is not the same as two weeks of "verified safe." Any organization that closed the ticket on September 9 without checking for prior compromise should reopen it and look backward, not just confirm the patch applied.

Certificate-based authentication is usually the more secure configuration choice, which is exactly what makes the Arista flaw notable: it only affects orchestrators using certificates, not the weaker pre-shared-key mode. Do not assume the more secure option in any vendor's configuration guide is immune to a given flaw; check the advisory for your specific setup every time.

Action checklist
  1. Inventory F5 BIG-IP APM deployments, confirm whether APM is configured as an OAuth Authorization Server with an access policy on any virtual server, and apply F5's hotfix immediately if so.
  2. Patch Check Point Management Server products to R82.20 or the relevant jumbo hotfix accumulator rather than relying on LivePatch, and separately confirm every Spark Security Gateway received the September 9 fix for CVE-2026-85102.
  3. Determine whether your Arista VeloCloud Orchestrator authenticates Edges by certificate; if so and you are on the 6.1 or 7.0 train awaiting a fix, restrict the VCO web interface to trusted administrative networks and monitor for Arista's published indicators now.
  4. For all three vendors, pull the published indicators of compromise and check logs from before the KEV addition date, not only going forward, since exploitation predates public disclosure in at least two of these cases.

A security vendor's own offboarding gap let attackers walk off with 170 private repositories

NOTABLE · SUPPLY CHAIN LESSON
Key facts
Victim: CrowdSec, a French threat-intelligence and open-source security vendor
Incident window: May 22, 2026, roughly 9 minutes (5:52 to 6:01 am UTC)
Root cause: a former employee's still-active GitHub org access, combined with an OAuth token stolen via the May 2026 TanStack npm supply chain attack
Repositories taken: about 300 total, including roughly 170 private repositories (SaaS console source, some AWS routines, connectors, automations)
Discovery: September 16, 2026, when an archive of CrowdSec's GitHub source appeared on the underground marketplace pwnforum
Access revoked: the departed employee's account was removed from GitHub on May 25, three days after the theft
Gap acknowledged: CrowdSec's CEO says the company did not have endpoint detection and response enforced on developer machines at the time

What happened

CrowdSec traced an attacker's activity to May 22, when someone using an IP address in Toronto downloaded the contents of CrowdSec's GitHub repositories in a roughly nine-minute window. The company only learned of the theft on September 16, when a user posted an archive of the stolen source code on the cybercrime marketplace pwnforum; the tip came from a group called Fuites Info. Investigating with GitHub's help, CrowdSec traced the access to an OAuth token that no longer existed in its own audit records, and eventually to the account of a developer who had recently left the company but whose GitHub organization access had been kept active so he could finish outstanding work.

That former employee's machine had been compromised through the May 2026 TanStack npm supply chain attack, in which a group calling itself TeamPCP published 84 malicious artifacts across 42 TanStack packages. CrowdSec had used a TanStack package around that time, and the malware likely stole the API token that let the attacker read the private codebase. CrowdSec removed the departed employee's account from GitHub on May 25, three days after the theft occurred, and says the leak is limited to source code: no customer credentials, infrastructure access or databases were confirmed compromised, and the company found no evidence the attackers altered any code.

CrowdSec's CEO, Philippe Humeau, acknowledged in the company's public disclosure that the firm had strict privilege separation, two-factor authentication, password wallets, logging, penetration testing and audits in place, but had not enforced endpoint detection and response on developer machines at the time of the incident, calling it something the company "should have done earlier."

Evidence

Verified against two independent sources:
1. Dark Reading, "Shai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub Data," September 22, 2026
2. SecurityWeek, "CrowdSec Confirms Source Code Stolen in Supply Chain Attack," September 21, 2026

What this means for your team

Offboarding is a security control, not an HR formality. A vendor with two-factor authentication, privilege separation and regular audits was still exposed because one departed employee's access lingered for a task that could have been handled another way. The failure here is a process gap, not a missing technology.

Developer endpoints are attack surface regardless of how mature your security program otherwise is. CrowdSec is a security company, and it was still caught without EDR on the one class of machine that holds the credentials attackers actually want. If your developer workstations are exempted from endpoint monitoring for productivity reasons, this incident is the argument against that exemption.

Treat your own source code as sensitive data before an attacker forces the point. CrowdSec's own leadership now recommends scanning repositories for hardcoded secrets proactively and assuming that anything ever committed to a private repository is one bad day from becoming public.

Action checklist
  1. Audit the last 90 days of employee departures against current GitHub, GitLab and CI/CD access lists, and confirm access was revoked the same day in every case.
  2. Deploy endpoint detection and response, or an equivalent control, on every workstation with GitHub organization membership or pipeline credentials, with no productivity-based exemptions.
  3. Check whether your organization used TanStack packages during the May 2026 exposure window, and rotate any credentials that were live on affected developer machines at the time.
  4. Run a secrets-scanning pass across your private repositories now, on the assumption that source code exposure is a matter of when, not if.

Also notable

Items that scored well on our ranking but sat below the threshold for full treatment today. Each is sourced; none has been verified to the two-source standard we apply above.

  • Security researcher Abdelhamid Naceri, known as Nightmare Eclipse, published a Windows Defender denial-of-service zero-day called BigDiskBuster that blocks Defender from receiving signature and platform updates on all supported Windows versions; it is part of a string of nearly a dozen disclosures he has made since April amid a dispute with Microsoft, and remains unpatched. BleepingComputer
  • WordPress shipped version 7.1.2 on September 22, patching a second and separate critical unauthenticated flaw, CVE-2026-87902 (CVSS 9.2), affecting every version back to 4.7.0, including sites that had already updated to 7.1.1 days earlier for the unrelated Click2Shell issue. SecurityWeek
  • Cisco Talos documented ClosedQuorum, the first publicly known Windows malware that queries four AI models, Gemini, DeepSeek, Qwen and Mistral, and decides its next post-compromise action by majority vote among their responses; researchers say they have not observed it deployed in the wild. BleepingComputer

FAQ

What is device-code phishing, and why does disabling it help?

Device-code phishing abuses the OAuth 2.0 device-authorization flow, a legitimate feature built for devices with limited input, such as smart TVs or printers. An attacker starts a device-code request and tricks a victim into entering the resulting code on Microsoft's real login page, which hands over a valid access token without any password being stolen. Most organizations do not need this flow for ordinary user accounts, so disabling it removes the entire attack path rather than just detecting it after the fact.

Was Microsoft itself breached by EvilTokens?

No. EvilTokens abused a legitimate Microsoft authentication feature to compromise individual customer accounts and organizations; it was not a breach of Microsoft's own systems. Microsoft led the disruption effort against the criminal service.

Has the FBI confirmed it was hacked by ShinyHunters?

No. The FBI has said only that it is aware of claims regarding unauthorized activity affecting its jobs website and is investigating. It has not confirmed a breach occurred or that any data was stolen. BleepingComputer, which first reported the claim in detail, says it has not independently verified the alleged zero-day, the lateral movement into AWS GovCloud, or the amount of data taken.

Why does a defaced website not prove a breach occurred?

Defacing a public-facing website demonstrates that an attacker gained some level of access to that specific site. It does not by itself prove broader claims made alongside it, such as lateral movement into separate cloud infrastructure or the volume of data taken. Independent verification of those specific claims is what would confirm or refute them.

What do the F5, Check Point and Arista flaws have in common?

All four vulnerabilities are critical-severity, unauthenticated flaws in network and access-management appliances, all were confirmed under active exploitation, and all were added to CISA's Known Exploited Vulnerabilities catalog on the same day. They affect three different vendors and different product lines, so the connection is the pattern and timing rather than a shared root cause.

Does patching an appliance vendor's flaw mean you were not already compromised?

No. In at least two of the cases covered today, exploitation was confirmed only after the flaw had already been patched or disclosed for some time, including a Check Point flaw where active exploitation was confirmed roughly two weeks after the patch shipped with no evidence of attacks at the time. Applying a patch closes the door going forward; it does not tell you whether someone already walked through it.

How did CrowdSec's own security controls fail to stop this breach?

CrowdSec had two-factor authentication, privilege separation, logging, penetration testing and audits in place. What it lacked was prompt offboarding of a departed employee's GitHub access and endpoint detection and response on developer machines. The breach occurred because a former employee's still-active account was used with a token stolen from his personal machine.

What is ClosedQuorum, and is it an active threat today?

ClosedQuorum is a Windows malware family documented by Cisco Talos that sends reconnaissance data from a compromised machine to four AI models and lets their combined responses decide its next action. Talos describes it as the first publicly documented malware to use this approach, but researchers say they have not observed it deployed against real victims, so it is a demonstrated capability rather than a confirmed in-the-wild threat at this time.

CISO Platform Breach Intelligence Team
Curated by Pritha Aash, Community Head, CISO Platform. Breach Watch is a daily briefing for senior security leaders, built from verified reporting and written for the person who has to decide what the team does about it before lunch.
NETWORK · SHARE · LEARN
Security leaders compare notes on incidents like these every day inside the CISO Platform community. Joining is free.

Related reading from the community: past editions and analysis in the Breach Intelligence briefing archive, practitioner material on identity and access management for OAuth and device-code flows, guidance on building a vulnerability management program around exploited flaws, and the wider library of frameworks and checklists on CISO Platform.

Corrections and takedown requests: CISO Platform is committed to accuracy and fairness. If any detail in this briefing is inaccurate, or if you represent an affected organization and would like a correction or removal, please contact us at pritha.aash@cisoplatform.com and we will review your request promptly.

You need to be a member of CISO Platform to add comments!

Join CISO Platform

Join The Community Discussion