Technology

Microsoft disrupts EvilTokens phishing service linked to 12,000 inboxes

Microsoft says a court-authorized operation seized websites and domains used by EvilTokens, an AI-assisted phishing service.

Hana Yoshida

By Hana Yoshida · Markets Reporter

3 min read

Microsoft disrupts EvilTokens phishing service linked to 12,000 inboxes
Photo: Ars Technica

Microsoft said it has disrupted EvilTokens, a subscription phishing service linked to more than 12,000 compromised email inboxes at more than 10,000 organizations. The Microsoft EvilTokens disruption targeted a service that paired a known login-phishing tactic with AI tools that could sort through stolen mailboxes and prepare fraud attempts.

Microsoft said the action was authorized by the U.S. District Court for the Eastern District of Virginia and was carried out with Health-ISAC, technology and security companies, and law-enforcement partners. The company said it seized 50 websites used by the service and disabled more than 150 supporting domains, but did not say the threat had been eliminated permanently.

According to Microsoft, the Metropolitan Police Service's cybercrime team arrested two men, ages 32 and 38, on Sept. 11 on suspicion of offenses connected to the alleged operation. Microsoft said officers seized digital devices and other items for examination.

How did EvilTokens compromise email accounts?

Microsoft said EvilTokens abused device-code authentication, a legitimate OAuth sign-in method intended for devices such as TVs and other hardware with limited input options. In a normal flow, a device displays a short code that a user enters in a browser on another device to complete its sign-in.

In the phishing version, attackers initiated the authorization request, then persuaded targets to enter a displayed code at a genuine Microsoft sign-in page, Microsoft said. That approved the attacker’s session without requiring the target to disclose a password. Microsoft said this method can bypass traditional multifactor-authentication protections because the browser authentication occurs separately from the session originally requested by the attacker.

Once a session token was obtained, the service’s AI tools could summarize and translate email, identify payment discussions, map organizational roles and flag trusted contacts for impersonation, according to Microsoft. The company said this enabled users of the service to identify people with authority over payments and prepare convincing follow-up messages aimed at moving funds.

What organizations were affected?

Microsoft said the highest concentrations of observed victim activity were in the United States, Canada, the United Kingdom, Australia, India and France. Affected sectors included wholesale distribution, construction, financial services, real estate, higher education and healthcare.

The service emerged in February 2026 and was sold through Telegram for a $1,500 initiation fee and a $500 monthly subscription, Microsoft said. Microsoft assessed that AI reduced the time attackers would otherwise spend manually reviewing messages and assembling information about an organization’s payment processes and relationships.

Microsoft advised organizations to restrict or block device-code authentication where it is not needed. After a suspected compromise, the company said, organizations should revoke active sessions and tokens as well as reset passwords, and independently confirm unusual requests involving payment changes, redirected funds or transaction approvals through a trusted second channel.

This story draws on original reporting from Ars Technica.