Microsoft Disrupts EvilTokens Phishing Service

Microsoft and its partners disrupted EvilTokens infrastructure that, according to the company, helped attackers access email inboxes through phishing abuse of the device code flow.

The EvilTokens phishing service was reportedly used for attacks through the OAuth device code flow and for stealing access tokens. On September 22, 2026, the company announced a coordinated action with partners in which 50 websites were seized and more than 150 domains supporting the infrastructure were deactivated.

According to Microsoft, the service had operated since February 2026 and affected more than 12,000 email inboxes across over 10,000 organizations worldwide. These figures are based on Microsoft’s findings; neither a complete public list of victims nor court records independently confirm them.

The EvilTokens phishing service abused the device code flow

The device code flow is an authentication mechanism intended primarily for devices or environments where standard browser-based sign-in is inconvenient. In the phishing variant, the attacker persuades the victim to enter the displayed code on Microsoft’s legitimate sign-in portal and log in. The victim therefore may not hand over a password directly on a fraudulent website, but may authorize a session controlled by the attacker.

This process can bypass the protective benefit of multifactor authentication when a user personally approves the fraudulent authorization. After obtaining the token, an attacker may, according to Microsoft, access an email inbox, create malicious rules, conduct reconnaissance through Microsoft Graph, and prepare business email compromise (BEC) scams.

AI was reportedly used to tailor lures and select targets

Microsoft said EvilTokens used artificial intelligence tools to customize phishing lures. AI was also reportedly used to analyze the content of compromised inboxes and help select valuable targets for BEC scams, in which attackers impersonate a trusted contact to solicit payment or sensitive data.

In this case, according to Microsoft, AI was not used only to create more convincing message text, but also to identify business relationships and potential opportunities for financial fraud in already compromised communications.

Recommendation: Block the device code flow if it is not needed

Microsoft recommends that organizations block the device code flow unless they need it. If its use is unavoidable, exceptions should be narrowly limited to specific required accounts and devices.

When investigating a possible incident, it makes sense to check for suspicious device registrations, rules created in email inboxes, and activity related to Microsoft Graph. Organizations should also monitor new domains, clones, or phishing campaigns that may use the same technique after the disruption of the original infrastructure.

Disrupting operations does not mean the threat has been confirmed to be completely eliminated. Service operators or users may create new infrastructure or move their techniques to other platforms. Microsoft also mentioned the arrest of two men in the United Kingdom in its announcement, but the available materials do not include a separate public police announcement directly related to this case.

Further information may emerge through the publication of court documents, the identities of suspects, or investigation results. It is also not publicly confirmed which affected organizations experienced specific BEC incidents or financial losses.

Sources

  • Microsoft Security Blog – Microsoft’s technical explanation of how EvilTokens operated, the extent of compromises it observed, and recommended mitigations.
  • Microsoft On the Issues – Announcement of the disruption, the number of websites seized and domains deactivated, and the claim concerning arrests in the United Kingdom.
  • Ars Technica – Independent coverage of Microsoft’s announcement and the context of device-code authentication abuse.

Verified and updated: September 23, 2026 06:25

Sharing