Summary
- EvilTokens, a device-code phishing kit sold as a subscription service, compromised 12,000 Microsoft 365 inboxes across more than 10,000 organisations since launching in February 2026.
- The service used an AI chatbot to analyse compromised inboxes and guide criminals on who to target, which contacts to impersonate, and which fraud tactics to deploy.
- London’s Metropolitan Police arrested two suspected administrators, aged 32 and 38, on 18 September; both have been released on bail pending further investigation.
- Microsoft seized 50 operational websites and disabled more than 150 supporting domains; affected customers are being notified and assisted with remediation.
- Microsoft’s Digital Crimes Unit describes this as its first court-authorised action against an end-to-end AI-enabled cybercrime service.
What Was Disrupted
EvilTokens emerged in February 2026 as a phishing-as-a-service platform built around Microsoft’s device-code authentication flow. By renting access to the kit, criminal buyers could silently authenticate as a victim against Microsoft 365 without ever needing to defeat multi-factor authentication directly. Within months of launch, the service had been used to compromise 12,000 email inboxes spanning more than 10,000 organisations globally. Microsoft’s VP of security research, Tanmay Ganacharya, told The Register that between 10 and 15 distinct campaigns were launching every 24 hours from 15 March 2026 onwards.
The AI Angle
What distinguished EvilTokens from comparable phishing kits was an integrated AI chatbot. Once an inbox was accessed, the chatbot could analyse its contents and surface intelligence that guided follow-on fraud: who the account holder communicated with, which contacts carried authority or trust, and which deception strategies were most likely to convert. Microsoft’s Digital Crimes Unit has described this as its first action against an end-to-end AI-enabled cybercrime service — a meaningful marker of how criminal tooling is evolving.
The Takedown
The disruption was coordinated across the United States and United Kingdom. Following authorisations from the US District Court for the Eastern District of Virginia, Microsoft and co-plaintiff Health-ISAC worked alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs to take down EvilTokens’ platform. Microsoft seized 50 websites used to operate the service and disabled more than 150 additional domains supporting its infrastructure. Health-ISAC joined the legal action as a co-plaintiff given that healthcare organisations were among those targeted. Separately, London’s Metropolitan Police arrested two men — aged 32 and 38 — who are alleged to have administered the EvilTokens platform. Both were arrested on 18 September and have since been released on bail while the investigation continues.
Victim Notification Under Way
Microsoft has begun notifying affected customers and is assisting with remediation of compromised accounts. The company’s Digital Crimes Unit noted this action represents its 40th court-authorised disruption over nearly two decades of operation.
The Residual Risk
Despite the takedown, the DCU’s associate general counsel Steven Masada was direct about what remains. “The infrastructure supporting EvilTokens has been disrupted, but the model it demonstrated will not disappear with it,” he stated in a blog shared with The Register ahead of publication. The phishing-as-a-service model is well established, and AI-augmented variants are now a demonstrated reality rather than a theoretical concern.
Why it matters
EvilTokens confirms two trends CISOs should treat as settled assumptions rather than emerging threats: device-code phishing that circumvents MFA is operationally mature and available at scale, and AI is now being used not just to craft lures but to automate post-compromise exploitation of inbox content. The speed implication is significant. As Masada noted, once an inbox is compromised, criminals may understand its contents in minutes. That compresses the window between initial access and business-email-compromise fraud to a timeframe that traditional detection and response cycles were not designed to handle. Healthcare organisations were explicitly targeted, and the breadth — more than 10,000 organisations — suggests no sector should consider itself low-priority for this class of attack.
What to do now
- Review whether your Microsoft 365 environment permits device-code authentication flows, and restrict or disable them where they are not operationally required.
- Implement independent verification procedures — via a trusted second channel — for any requests to change payment information, redirect funds, or approve unusual financial transactions, regardless of whether the instruction appears to come from a known internal contact.
- Establish inbox monitoring controls that can detect silent authentication events and anomalous access patterns indicative of token-based compromise.
- If your organisation uses Microsoft 365, check whether you have received notification from Microsoft regarding compromised accounts and act on remediation guidance promptly.
- Brief finance, procurement, and executive-support teams on the speed at which AI-assisted BEC fraud can follow an initial inbox compromise — awareness of the compressed timeframe should inform escalation and verification culture.
