Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
Microsoft dismantled EvilTokens, an AI-assisted device-code phishing service linked to about 12,000 inbox takeovers.
Microsoft's Digital Crimes Unit, under an order from the U.S. District Court for the Eastern District of Virginia and with partners including Health-ISAC, Cloudflare, Coinbase, and OpenAI, dismantled EvilTokens, a phishing-as-a-service platform tied to about 12,000 inbox compromises. Microsoft tracks the operators as Storm-2992, and the Metropolitan Police Service arrested two men, ages 32 and 38, on September 11, 2026. The kit abused the OAuth 2.0 device-code flow so victims entered codes at Microsoft's real login page, giving attackers access and refresh tokens used for mailbox theft, hidden inbox rules, and business email compromise. Products sold for $600 to $1,500 plus a $500 monthly fee, and Coinbase traced about $1.1 million in Tron revenue from October 2025 to June 2026.