EvilTokens: AI-Powered Phishing Operation Compromises Thousands of Microsoft Inboxes
A sophisticated phishing operation, dubbed EvilTokens, compromised over 12,000 Microsoft inboxes across more than 10,000 organizations. The attackers used device-code authentication and AI to automate reconnaissance and impersonation, transforming trusted login infrastructure into a scalable business-email-compromise service.
The platform sent victims codes through emails disguised as invoices or shared files, and when the target entered the code on Microsoft's legitimate site, the attacker's waiting session became authorized. This workflow avoided capturing passwords directly while still giving criminals access to victim mailboxes.
EvilTokens then automated tasks traditionally requiring manual reconnaissance, such as summarizing messages, identifying reporting lines, locating pending invoices, and determining which employees had authority over payments.
Coinbase's Global Intelligence team tracked $1.1 million in EvilTokens platform revenue across four TRON addresses between October 2025 and June 2026, identifying more than 1,000 deposits from over 700 addresses.