Microsoft Dismantles EvilTokens Phishing Service After Seven-Month Run
Microsoft's Digital Crimes Unit (DCU) has dismantled EvilTokens, a seven-month-old phishing service that compromised over 12,000 Microsoft 365 inboxes across more than 10,000 organizations worldwide. The takedown, which was backed by a federal court order from the Eastern District of Virginia, seized 50 websites and disabled more than 150 supporting domains.
The AI-powered phishing service, which launched quietly in February 2026, sold itself as a subscription product with 24/7 support, offering customers access to a dashboard, hosting, phishing templates, and an AI assistant that generated lures and coached buyers through each step of a device-code phishing attack.
Evidence shows that EvilTokens did not break Microsoft's login page or exploit a software bug. Instead, it abused a legitimate authentication feature called OAuth's device authorization flow, which lets devices without browsers link to a user's account by displaying a short code the user types into a trusted sign-in page on a second device.
The service targeted distracted employees with AI-generated messages tailored to their role or company, tricking them into visiting Microsoft's real login page and entering a legitimate code. The resulting authorization token was then handed over to the attacker's session, giving them live access to the victim's mailbox without ever touching a password.