Microsoft Shuts Down AI-Powered Phishing Platform Compromising Thousands of Email Accounts
A powerful AI-powered phishing platform called EvilTokens has been disrupted by Microsoft. The platform was used to target over 10,000 organizations in several countries worldwide, compromising more than 12,000 email accounts.
EvilTokens emerged in February 2026 and allowed cybercriminals to use device code authentication flow designed for devices that don't support standard login methods. This method involves entering a short code presented on the device into a web browser session on a separate device. Threat actors can abuse this by initiating the authentication flow and providing the code to the targeted user via a phishing lure.
The platform used AI throughout the attack chain, including creating customized phishing emails for specific targets. EvilTokens also offered 44 different themes for malicious emails and phishing pages. Once access was gained to an account, AI helped EvilTokens users go through victims' inboxes for valuable data.