Microsoft Disrupts AI-Powered Phishing Platform EvilTokens
Microsoft has disrupted EvilTokens, an AI-powered phishing platform used by cybercriminals to target over 10,000 organizations worldwide. The platform, which emerged in February 2026, was used to compromise more than 12,000 email accounts across multiple countries.
EvilTokens employed device code phishing, a tactic that targets the device code authentication flow designed for devices without standard login methods. Threat actors initiated the authentication flow and provided the code to the targeted user via a phishing lure, allowing them to gain access to the account without obtaining passwords.
The platform used AI throughout the attack chain, including creating customized phishing emails with 44 different themes. Once access was gained, AI helped EvilTokens users navigate victims' inboxes for valuable data and decide who to target, impersonate, and exploit.
Microsoft seized 50 websites used to run the service and disabled more than 150 other domains linked to the platform's infrastructure. The company also arrested two men suspected of being involved with EvilTokens: Felix Utomi and Waidi Segun Adams.