Microsoft and Global Partners Disrupt EvilTokens Phishing Platform Targeting Thousands Worldwide

EvilTokens reportedly launched on Telegram in mid-February 2026 and was first publicly documented by cybersecurity researchers at Sekoia in March, indicating how quickly the service moved from launch to widespread abuse.
The platform offered 44 phishing themes, allowing customers to tailor lures for different campaigns and victims.
SpyCloud’s independent analysis identified 8,708 compromised accounts across 6,585 domains in 79 countries, a separate estimate that provides additional detail on the geographic and organizational reach of the operation.
Microsoft 365 organizations affected by campaigns using EvilTokens included wholesale distribution, construction, financial services, real estate, higher education and healthcare, showing that the targeting crossed multiple economic sectors.
The device-code technique exploited the legitimate OAuth authorization flow originally designed for devices such as smart TVs and other hardware without keyboards. Because victims completed genuine password and MFA prompts, the method could evade MFA protections; the attacker’s malicious step was generating and presenting the code that authorized the attacker’s session.
Microsoft's Digital Crimes Unit disrupted EvilTokens, a phishing-as-a-service platform that compromised more than 12,000 Microsoft 365 inboxes across over 10,000 organizations worldwide. Microsoft seized 50 websites and disabled more than 150 related domains through court-authorized action after the platform launched in February 2026 and spread rapidly. The scheme is linked to threat actor Storm-2992 and at least $1.7 million in reported losses.
EvilTokens used device-code phishing to trick victims into authorizing attackers' sessions on genuine Microsoft login pages. Even after victims completed password and multifactor authentication checks, attackers stole session tokens that gave them access to email, inbox rules, and internal company data. Huntress documented how the platform abused OAuth 2.0, a legitimate security standard originally designed for smart TVs and devices without keyboards.
The platform exploited a flaw in how device-code authentication works. Victims saw real Microsoft password prompts and entered genuine credentials plus multifactor codes. But attackers secretly generated authorization codes that let them access the same accounts. TechSpot reported that because victims completed authentic security checks, traditional fraud detections failed to catch the attack.
Once inside, attackers used artificial intelligence to scan inboxes for payment details, wire transfer instructions, and trusted business relationships. The AI chatbot could even draft convincing messages impersonating company employees to commit fraud. Microsoft stated the platform offered 44 customized phishing templates, allowing criminals to tailor lures for different victim organizations.
EvilTokens launched on Telegram in mid-February 2026 and was publicly documented by Sekoia researchers by March. The service charged $1,500 to start plus $500 monthly, attracting cybercriminals quickly. SpyCloud's independent analysis found 8,708 compromised accounts across 6,585 domains in 79 countries, showing global scale within weeks.
Victims spanned wholesale distribution, construction, financial services, real estate, higher education, and healthcare. This broad targeting showed attackers used automation to cast wide nets rather than focus on specific industries. Microsoft noted the platform's AI capabilities let criminals identify targets and launch business-email-compromise campaigns in minutes, not hours.
In September 2026, London Metropolitan Police executed search warrants at addresses in Canary Wharf and Nine Elms based on actionable intelligence. Two men, aged 32 and 38, were arrested on suspicion of operating EvilTokens. Both were released on conditional bail as investigations continue. Detective Inspector Serena D'Adamo said authorities remain committed to holding accountable those who "facilitate criminal enabling functions."
Microsoft officially announced the takedown on September 22, 2026, after working with the FBI, Health-ISAC, Cloudflare, Coinbase, OpenAI, and other partners. The disruption seized infrastructure but cybersecurity experts warn that the OAuth device-code vulnerability remains built into authentication standards. Organizations must revoke active session tokens, not just reset passwords, to fully eject attackers who stole tokens that stay valid for up to 90 days.
Publishers
30
Articles
10
Reach
40