Microsoft says it has disrupted EvilTokens, a phishing-as-a-service platform that combined Microsoft 365 token theft with AI-assisted mailbox analysis for business email compromise.
According to Microsoft, EvilTokens was linked within months to more than 12,000 compromised email inboxes across over 10,000 organizations worldwide. The highest concentrations of observed victim activity were in the United States, Canada, the United Kingdom, Australia, India, and France.
Microsoft’s Digital Crimes Unit announced the operation on September 22, 2026. The company said it worked with Health-ISAC as a co-plaintiff and obtained authorization from the U.S. District Court for the Eastern District of Virginia to act against infrastructure tied to the service.
Microsoft said the coordinated action seized 50 websites used to operate EvilTokens and disabled more than 150 additional domains tied to supporting infrastructure. The company also named Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs among partners involved in the operation.
In the United Kingdom, Microsoft said the Metropolitan Police Service’s cybercrime team arrested two men, aged 32 and 38, on September 11, 2026, and seized digital devices and other items for examination. Microsoft said both men were released on police bail subject to conditions while the investigation continues.
Cloudflare’s Cloudforce One team separately said it joined Microsoft in a September 2026 operation and executed a technical takedown of Workers projects and infrastructure supporting the kit. SpyCloud said its recaptured EvilTokens data showed at least 8,708 unique victim accounts with device-code token capture across 6,585 corporate email domains in 79 countries, based only on SpyCloud’s own visibility.
How EvilTokens turned device sign-ins into inbox access
Device-code authentication is a legitimate OAuth flow used for devices with limited input, such as TVs, printers, Teams devices, and conferencing hardware. In a normal setup, a device shows a short code and the user enters that code in a browser to finish signing in.
In a device-code phishing attack, the attacker starts the sign-in request and sends the code to the victim through a lure. The victim may complete sign-in and MFA on Microsoft’s real login page, but the session being authorized belongs to the attacker. The password is not necessarily stolen, which makes the attack harder to recognize as ordinary credential theft.
Microsoft Threat Intelligence tracks the threat actor behind EvilTokens development and support as Storm-2992. Microsoft said the service was advertised and sold through Telegram, with a $1,500 initial purchase and a $500 monthly subscription for continued access to the kit and control panel.
The EvilTokens panel offered prebuilt phishing templates, attachment files, hosting and domain configuration, redirect logic, and victim tracking. Microsoft said campaigns used 44 different lure themes, including invoices, requests for proposals, and shared files.
The AI piece changed the damage after compromise
Microsoft said EvilTokens used an AI-style chatbot to analyze compromised inboxes, summarize and translate messages, identify trusted relationships, map organizational roles, surface financial conversations, find payment-related responsibilities, and recommend possible fraud strategies. Preset prompts reportedly searched for wire-transfer discussions, vendor invoices, money movers, and people worth impersonating.
That compressed the time between account compromise and fraud planning. A stolen inbox could be turned into a guided fraud workflow, instead of requiring a criminal to manually read thousands of messages and understand the organization from scratch.
The legal case is still moving
In its civil complaint, Microsoft and Health-ISAC allege that the defendants operated technologies and infrastructure that stole device-level authentication tokens and used stolen access to scan inboxes at scale. The complaint names Felix Utomi, Waidi Segun Adams, and Does 1-5 as defendants. Those are civil allegations, and the claims have not been tested to final judgment in court.
Microsoft’s public Digital Crimes Unit notice lists the case as Civil Action No. 1:26-cv-3047 in the U.S. District Court for the Eastern District of Virginia.
The notice says Microsoft obtained a temporary restraining order and is seeking a preliminary injunction directing registries and registrars connected to listed domains to transfer domains to Microsoft’s control or disable access and operation. The pleadings page also lists an order directing defendants to show cause on October 10, 2026.
Microsoft said the action is the Digital Crimes Unit’s 40th court-authorized disruption and its first against what it describes as an end-to-end AI-enabled cybercrime service.
What Microsoft 365 administrators should take from this
The disruption removes infrastructure Microsoft tied to EvilTokens, but it does not remove the legitimate authentication flow the service abused. Other groups can copy the technique, and device-code phishing remains a tenant-level identity risk where the flow is still broadly allowed.
For Microsoft 365 environments, the practical security question is whether device-code authentication is needed at all. Microsoft recommends blocking device-code flow wherever possible. Where Teams room devices or other limited-interface devices require it, exceptions should be narrowly scoped to the correct resource accounts and excluded from broader device registration access.
- Limit device-code authentication. Microsoft recommends allowing it only where necessary and managing it through Conditional Access policies.
- Watch for token and device signals. Microsoft’s detection guidance points to anomalous OAuth device-code authentication, anomalous token exchange, suspicious Entra device join or registration, unusual Microsoft Graph API activity, and suspicious inbox-rule creation.
- Treat mailbox rules as compromise evidence. EvilTokens activity included persistence and defense evasion using inbox access, so hidden forwarding, deletion, or folder rules deserve fast review.
- Do more than reset the password. Microsoft says suspected device-code phishing response should include revoking refresh tokens, considering forced reauthentication, and temporarily disabling a compromised account when immediate containment is needed.
- Verify payment changes outside email. Microsoft’s warning about inbox analysis makes out-of-band confirmation more important for vendor banking changes, urgent payment approvals, cryptocurrency transfers, and executive requests.
Microsoft also said observations from recent campaigns indicate that standard session revocation often invalidates refresh tokens while existing access tokens may remain active for about an hour. In hands-on attacks, that window can be enough for attackers to keep moving.
The most reusable part of the EvilTokens model is the pairing of trusted sign-in flows with machine-speed reconnaissance after access is granted.

Tech Help Canada Staff researches, writes, and reviews practical content for business owners and professionals. Our coverage spans business, marketing, SEO, technology, and the tools and systems people use to grow and operate online. We focus on clear, useful information backed by research, hands-on experience, and editorial review. Learn more about our team and editorial standards. Need help with something? Contact Us







