More than 12,000 compromised email inboxes across over 10,000 organizations worldwide, Microsoft said, marking the scale of an AI‑assisted phishing service it and partners moved to dismantle this month.
Court‑authorized takedown led by Microsoft with private partners and U.K. arrests
Microsoft announced on Tuesday a court‑authorized disruption of the EvilTokens device‑code phishing service, with authorization obtained from the U.S. District Court for the Eastern District of Virginia. The action involved Health‑ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs. The company said it is tracking the developers and supporters of EvilTokens as the actor known as Storm‑2992.
Separately, the Metropolitan Police Service arrested two men, aged 32 and 38, on September 11, 2026, in connection with the platform's commercial operation. Microsoft said the effort seized 50 websites used to operate the service and disabled over 150 additional domains associated with its supporting infrastructure.
How the device‑code phishing flow and delivery pipeline worked
EvilTokens abused the OAuth 2.0 device authorization flow to obtain access and refresh tokens without requiring victims to hand over their passwords. The malicious lure presented a live device code and a button that sent victims to the legitimate microsoft.com/devicelogin portal, where pasting the code completed authentication for the attacker’s client. Once issued, the access and refresh tokens gave attackers ongoing access under the victim's identity and could persist after password resets unless sessions and tokens were revoked.
The infection chain typically began with deceptive email themes — invoices, RFPs, shared files and 44 other lures — containing URLs, PDF attachments, or HTML files that redirected victims to a page running a background automation script. That script communicated with Microsoft's identity provider in real time to generate the device code shown to the victim.
To evade detection, the service used a multi‑stage delivery pipeline that relied on fake CAPTCHA checks and high‑reputation "serverless" platforms such as Vercel, Cloudflare Workers, and AWS Lambda, allowing malicious traffic to blend with legitimate enterprise cloud traffic and bypass domain‑blocklist triggers and traditional gateways.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleAI at the center: mailbox analysis, target selection, and fraud tooling
Microsoft described EvilTokens as centering on "an AI‑style chatbot that could analyze a victim's inbox and help criminals identify trusted relationships, payment authorizations, and sensitive responsibilities" and could "recommend fraud strategies, including drafting messages that impersonated trusted contacts" — language attributed to Steven Masada, associate general counsel and general manager at Microsoft's Digital Crimes Unit.
TRM Labs called the platform a "powerful cybercrime platform" that "packaged account takeover, AI‑driven mailbox analysis, and fraud tooling into a single commercial service, lowering the expertise once needed to run business email compromise and invoice fraud at scale." Sekoia reported that EvilTokens had been sold as a phishing‑as‑a‑service offering on Telegram since mid‑February 2026 with AI features to automate business email compromise workflows.
The service provided auxiliary tools — Antibot redirector, B2B Sender, Office 365 Capture Link, and SMTP Sender — and offered preset prompts to locate wire‑transfer discussions, money movers, vendor invoices, and the best people to impersonate.
Scale, monetization, and forensic traces
Microsoft linked EvilTokens to more than 12,000 compromised inboxes in over 10,000 organizations, with concentrated victim activity in the U.S., Canada, the U.K., Australia, India, and France across sectors such as wholesale distribution, construction, financial services, real estate, higher education, and healthcare.
SpyCloud provided recaptured phished data that included 8,708 unique victim accounts spanning 6,585 corporate email domains in 79 countries, with the earliest captures dated February 18, 2026. Coinbase traced about $1.1 million in platform revenue across four Tron addresses from October 2025 to June 2026, and identified more than 1,000 deposits to EvilTokens from over 700 distinct crypto addresses.
Sekoia and Microsoft detailed pricing tiers: EvilTokens sold a B2B sender for $600, an Office 365 capture link (the device‑code phishing kit) for $1,500 with a $500 monthly licence fee for the phishing page code and API access, and an SMTP sender for $1,000; the service also charged a $500 monthly subscription for continued access to the kit and control panel.
What this means for technologists, enterprises, and the general public
- Technologists and security teams: expect attacks that abuse legitimate authentication flows and cloud platforms; the takedown shows coordination across hosting, model, and crypto providers can disrupt infrastructure quickly, but token revocation and session hygiene remain crucial to remove persistent access.
- Affected enterprises and procurement leaders: organizations in finance, higher education, healthcare, real estate, construction, and distribution should review token session logs, inbox rule changes, and vendor‑wire processes — the toolkit specifically automated identification of "money movers" and invoice threads.
- End users and email recipients: attackers using EvilTokens relied on realistic prompts that directed victims to the official microsoft.com/devicelogin page — completing that normal authentication flow handed attackers access without revealing passwords.
Microsoft and its partners describe the action as meaningful because EvilTokens was the first to scale device‑code phishing with a commercially packaged, AI‑assisted fraud workflow. The disruption seized operational sites and halted supporting domains, but the platforms, pricing, and tools laid out in the service's infrastructure and marketing suggest adversaries had already lowered the skill threshold for large‑scale business email compromise.




