Microsoft’s EvilTokens takedown sheds light on state of AI-powered cybercrime
Microsoft seized EvilTokens infrastructure after the AI phishing service compromised about 12,000 Microsoft 365 inboxes.
Microsoft disrupted EvilTokens, an AI-powered phishing-as-a-service platform active since February 2026 and linked to more than 12,000 compromised Microsoft 365 inboxes at over 10,000 organizations. The service abused the OAuth 2.0 device-code flow so victims entered a code on Microsoft’s real login page and handed over session tokens without passwords, then used an AI chatbot to mine mailboxes for business-email-compromise opportunities. Pricing was a $1,500 signup and $500 per month. A US court order let Microsoft seize 50 websites and more than 150 domains, and UK police arrested two men, ages 32 and 38, who were later released on bail. Coinbase traced about $1.1 million across more than 700 crypto addresses.
- More than 12,000 Microsoft 365 inboxes at over 10,000 organizations compromised
- Device-code phishing stole OAuth tokens without collecting passwords
- An AI chatbot scanned mailboxes to prepare business email compromise
- Microsoft seized 50 sites and over 150 domains under a US court order
- UK police arrested two suspected operators, both later released on bail
Full article555 words · extracted from csoonline.com · click to collapse
Microsoft has hailed its success in disrupting EvilTokens, an AI-powered a phishing-as-a-service (PhaaS) platform linked to more than 12,000 compromised Microsoft 365 inboxes across more than 10,000 organizations worldwide.
Since February 2026, EvilTokens has offered a subscription platform combining account compromise, mailbox analysis, target selection, and fraud preparation. Its dashboard and chatbot centralized access to those capabilities, with a $1,500 initial sign-up fee and $500 monthly subscription, marketed through Telegram channels.
“EvilTokens combined account compromise, mailbox analysis, target selection, and fraud preparation in a single service,” Microsoft explains in a post about the takedown. “Capabilities that once required experience across identity attacks, cloud systems, social engineering, and financial fraud were available through a ready-made interface.”
The cybercrime platform abusing Microsoft’s OAuth 2.0 device-code authentication flow to steal valid session tokens through device code phishing. If victims clicked on a link, they were shown a short-lived authentication code they were invited to submit through the real Microsoft device login page, unwittingly giving criminals access to their email accounts without revealing their passwords.
By stealing access tokens after a legitimate sign-in rather than going after passwords, attackers were able to surreptitiously gain persistent access to compromised Microsoft 365/Entra ID accounts.
Chatbot for cybercrime
The cybercrime platform also offered an AI-powered “analyst” chatbot that scanned compromised in-boxes to develop opportunities for financial fraud, such as business email compromise scams.
“EvilTokens uses tailored phishing messages to trick victims into authorizing attacker access through Microsoft’s legitimate sign-in process,” explained Jason Rivera, global field CISO at cyber range platform provider SimSpace. “Once inside, AI analyzes the mailbox to identify who controls payments, which business relationships carry trust, and which invoices or transactions present opportunities.”
Rivera, an ex-US Army threat intelligence officer, added: “It [EvilTokens] then recommends impersonation targets and helps draft fraudulent messages grounded in actual business conversations. Automated reconnaissance maps organizational permissions, while token refresh and inbox monitoring help maintain access and surface new opportunities.”
Affected organizations ranged from wholesale distribution and construction to financial services, real estate, higher education, and healthcare, according to Microsoft. Organizations across North America, the UK, France, India, and Australia were targeted through the scam.
Coinbase traced roughly $1.1 million in revenue from more than 700 distinct crypto addresses linked to the EvilTokens cybercrime operation.
Takedown
Microsoft was able to disrupt and dismantle the cybercrime operation after obtaining a US federal court order to seize 50 websites linked to EvilTokens and more than 150 associated domains as part of a coordinated takedown involving industry and law enforcement partners.
UK police arrested two men (ages 32 and 38) suspected of running the technology and infrastructure behind EvilTokens. Each has been released on police bail pending further enquiries, including the forensic examination of seized digital devices.
Device-code phishing defenses
Omair Manzoor, founder, CEO, and chief hacker at ioSENTRIX, an expert in offensive security, said the “takedown was successful because the operators made a classic infrastructure mistake — centralizable domains and traceable crypto payments.”
More sophisticated scams along the same lines are likely to follow, Manzoor warned.
“Organizations need to assume that every compromised mailbox will be read and exploited by AI within minutes, not days,” Manzoor advised. “Device-code phishing defenses — conditional access policies restricting device code flow, short token lifetimes, and anomalous authentication alerting — need to move from best practice to baseline immediately.”