Microsoft has successfully disrupted EvilTokens, an artificial intelligence-powered phishing-as-a-service operation connected to more than 12,000 compromised Microsoft 365 inboxes spanning over 10,000 organizations globally. The tech giant obtained a US federal court order to seize 50 websites associated with EvilTokens and more than 150 related domains as part of a coordinated operation with industry and law enforcement partners. UK authorities arrested two men, ages 32 and 38, suspected of operating the technology and infrastructure behind the cybercrime platform, though both were released on police bail pending further investigation.
EvilTokens launched in February 2026 as a subscription service charging $1,500 for initial enrollment and $500 monthly, marketed through Telegram channels. The platform exploited Microsoft's OAuth 2.0 device-code authentication flow to capture valid session tokens through device code phishing attacks. Victims who clicked malicious links received a short-lived authentication code that they were prompted to enter through Microsoft's legitimate device login page, unknowingly granting criminals access to their email accounts without exposing passwords. Organizations affected included those in wholesale distribution, construction, financial services, real estate, higher education, and healthcare across North America, the UK, France, India, and Australia. Coinbase tracked approximately $1.1 million in revenue from more than 700 distinct cryptocurrency addresses tied to the operation.
"EvilTokens combined account compromise, mailbox analysis, target selection, and fraud preparation in a single service," Microsoft explains in its takedown announcement. The company notes that "capabilities that once required experience across identity attacks, cloud systems, social engineering, and financial fraud were available through a ready-made interface." The platform featured an AI-powered "analyst" chatbot that examined compromised inboxes to identify opportunities for financial fraud, such as business email compromise scams. By capturing access tokens after legitimate sign-ins rather than targeting passwords, attackers gained persistent, covert access to compromised Microsoft 365 and Entra ID accounts.
The EvilTokens operation succeeded because it centralized previously fragmented criminal capabilities into a single dashboard, according to security experts cited in the report. Jason Rivera, global field CISO at SimSpace and former US Army threat intelligence officer, explained that once inside an account, artificial intelligence analyzed mailboxes to determine who controlled payments, which business relationships carried trust, and which invoices or transactions presented opportunities. The system then recommended impersonation targets and assisted in drafting fraudulent messages based on actual business conversations, while automated reconnaissance mapped organizational permissions and token refresh capabilities maintained access. Omair Manzoor, founder and CEO of ioSENTRIX, noted the takedown succeeded because operators made a "classic infrastructure mistake" with centralizable domains and traceable crypto payments.
Organizations must prepare for AI-powered analysis of every compromised mailbox within minutes rather than days, experts warn. Device-code phishing defenses—including conditional access policies that restrict device code flow, short token lifetimes, and anomalous authentication alerting—need to shift from best practice to baseline immediately, according to security professionals. More sophisticated scams following similar patterns are expected to emerge. The subscription model and centralized interface that made EvilTokens accessible to less technically skilled criminals represent a troubling evolution in cybercrime, lowering barriers to entry for attacks that once demanded specialized expertise across multiple domains. The board-level conversation will no longer center on whether credentials can be stolen, but on how quickly leadership can detect when the theft has already occurred and artificial intelligence is drafting the next fraudulent wire transfer on behalf of an adversary who never had to learn the underlying tradecraft.

