Security5 publishers3 min readPublished
EvilTokens rented an AI-powered inbox-scanning tool and a device-code MFA bypass for a $1,500 fee plus $500 a month
Microsoft's Digital Crimes Unit and its partners pulled down the EvilTokens phishing service about seven months after it launched, and British police arrested its two suspected operators. The authentication technique it sold survives on other platforms.
The Watch · Security desk

What happened
- Microsoft and partners seized 50 websites and disabled more than 175 domains supporting EvilTokens on a federal court order dated September 15, closing a service that had launched in February 2026.
- Investigators tie the platform to more than 12,000 compromised Microsoft inboxes at over 10,000 organisations, in sectors including wholesale distribution, construction, financial services and healthcare.
- About 1,000 cybercriminals bought access over the platform's life, sold through Telegram for a $1,500 initiation fee plus a recurring $500 a month.
- The Metropolitan Police served warrants in the greater London area on September 18, arrested two men accused of making articles for use in fraud and money laundering, and seized their digital devices.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint Seizing domains does not close the device-authorization flow, and at least nine other platforms were already selling the same technique as of April, so tenants that permit device-code sign-in stay reachable.
- exposure The flow hands over tokens and never touches a password, so a response that resets credentials and re-enrols MFA can leave a token holder reading the mailbox.
- capability Target selection and pretext drafting ran inside the victim's own mailbox, which leaves BEC controls tuned to unfamiliar senders and awkward wording with much less to grade.
- contradiction Microsoft's top victim countries include India and France while SpyCloud's ranking puts Saudi Arabia fifth, so a security team judging its own regional exposure gets a different answer depending on which dataset it reads.
The foothold came from Microsoft's own authentication design. EvilTokens sold device-code phishing, which abuses the OAuth 2.0 device-authorization flow, the path built for equipment with limited input such as smart TVs, printers and conferencing gear [23]. An attacker initiates a device-code request and sends the resulting code to the target inside a lure. The target reaches a page showing that code beside a button through to Microsoft's real login portal, and authenticates there [24]. The tokens come back to the operator. No credential is stolen and MFA is satisfied [22].
Microsoft calls EvilTokens the first such service to support device-code authentication at scale [21]. By April, at least ten phishing platforms supported the capability [25]. The takedown removed one of them.
Inside a mailbox, the platform used Microsoft Graph to map organisational relationships and permissions, then AI tooling to read mailbox content, search for wire-transfer details, pending invoices and executive correspondence, and generate business email compromise messages that fit the thread it found [26][27]. Stolen session tokens kept that access alive [7]. "AI was not simply helping attackers write more convincing messages. It helped them decide who to target, who to impersonate, and how to most effectively exploit the relationship to extract as much money as possible," Steven Masada, associate general counsel and general manager of Microsoft's Digital Crimes Unit, wrote [4]. OpenAI, Cloudflare, Health-ISAC, Shadowserver and TRM Labs took part in the disruption [32].
Coinbase traced about $1.1 million in revenue from the service's paying customers, spread over more than 1,000 deposits from more than 700 distinct addresses through June 2026 [19]. On the advertised rates, a full year of access cost $7,500, and the average deposit Coinbase saw was under $1,100 [1][2]. Anti-bot redirectors, B2B and SMTP sending tools and an Office 365 capture-link tool were priced separately, and the base service shipped 44 customisable phishing kits [29].
Confirmed victim losses are much thinner than the platform's revenue. Microsoft correlated 13 complaints filed with the FBI's Internet Crime Complaint Center to EvilTokens activity, about $1.7 million, an average near $131,000 per complaint [8][4]. "Because many incidents go unreported and not all victims can be definitively linked to specific campaigns, we believe this is a conservative estimate," a Microsoft spokesperson said [8].
Microsoft attributes development and support of the platform to Storm-2992 and says the actor is unaffiliated with any other known cybercrime group [14]. The Metropolitan Police received Microsoft's information on the administrators in August and executed warrants at addresses in Canary Wharf and Nine Elms [16]. Both men were released on bail and have not been publicly identified [17]. "The Met remains committed to holding people to account who facilitate criminal enabling functions and think they can remain undetected. We will find you and take action," Detective Inspector Serena D'Adamo told BleepingComputer [31]. Microsoft's legal filings, still sealed, refer to five more unidentified people as support personnel and users [18].
The two published victim geographies come from different datasets. Microsoft puts victims largely in the United States, Canada, the United Kingdom, Australia, India and France [9]. SpyCloud's recaptured data, reported by BleepingComputer, ranks the US first, then Canada, Australia, the UK and Saudi Arabia [10]. SpyCloud recovered 8,708 compromised accounts across 6,585 corporate email domains in 79 countries, roughly 73% of Microsoft's inbox figure, with about 97.5% of the accounts on enterprise domains [12][13][6]. Microsoft's 12,000 inboxes across more than 10,000 organisations average about 1.2 per victim organisation [5].
What to watch
- Whether Microsoft's sealed filings are unsealed and name the five additional support personnel and users.
- Whether the two men released on bail are charged, and whether the Metropolitan Police identifies them.
- Whether Microsoft changes defaults or tenant controls on the OAuth 2.0 device-authorization flow the platform abused.