Press play to start listening
Microsoft has disrupted EvilTokens, an AI-powered phishing-as-a-service platform linked to the compromise of more than 12,000 email inboxes across over 10,000 organisations worldwide since February 2026.
The coordinated operation resulted in the seizure of 50 websites used to operate EvilTokens and the disabling of more than 150 additional domains supporting the service. Authorities also arrested two men in the United Kingdom in connection with the alleged operation.
According to Microsoft’s Digital Crimes Unit, the operation was authorised by the US District Court for the Eastern District of Virginia. Health-ISAC also joined Microsoft’s legal case as a co-plaintiff because healthcare organisations were among the targets.
Microsoft worked with Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, the Shadowserver Foundation and TRM Labs to identify and disable infrastructure supporting EvilTokens. The company also contacted affected customers and helped them secure compromised accounts.
Two Men Arrested in the UK
Officers from the Metropolitan Police cybercrime team arrested two men, aged 32 and 38, on September 11, 2026. Police seized digital devices and other items for examination.
Police later released both suspects on conditional bail while the investigation continued. Neither man has been convicted, and Microsoft did not disclose their identities or alleged roles in the service.
Microsoft tracks the threat actor responsible for developing and supporting EvilTokens as Storm-2992. The service was advertised through Telegram for an initial fee of $1,500, followed by a $500 monthly subscription. Customers received phishing templates, hosting options, redirect tools, token-management features and technical support.
EvilTokens Used AI After Accounts Were Compromised
Microsoft said EvilTokens used AI for more than generating convincing phishing messages. Its chatbot could analyse compromised inboxes, identify employees authorised to make payments and map trusted relationships between victims, executives and outside organisations.
The system could search for invoices, wire-transfer discussions and executive correspondence before recommending who criminals should impersonate and how they could carry out financial fraud. Investigators also found indications that large parts of the EvilTokens platform itself had been developed with assistance from multiple AI models.
According to the company, EvilTokens abused Microsoft’s device-code authentication flow, a legitimate sign-in method intended for devices such as smart televisions, printers and conference-room equipment.
The platform allowed attackers to generate a device code and trick victims into entering it on Microsoft’s legitimate sign-in page. Those who completed the authentication process, including multifactor authentication when required, unknowingly authorised a session controlled by the attacker.
The stolen tokens could then provide mailbox access without revealing the victim’s password. Operators used malicious inbox rules, device registration and token-refresh mechanisms to maintain access and conceal communications.
Previous EvilTokens Campaigns
Hackread.com previously reported how EvilTokens was used with Outlook calendar invitations to place phishing messages directly into users’ schedules. The invitations remained visible even when the original emails were moved to junk or deleted.
A separate EvilTokens campaign exposed a visibility gap for enterprise security teams, as parts of the attack occurred through legitimate browser-based authentication and cloud services rather than traditional malware.
Microsoft observed the highest levels of EvilTokens activity in the United States, Canada, the United Kingdom, Australia, India and France. Affected organisations operated in financial services, construction, healthcare, higher education, real estate and wholesale distribution.
The company recommends blocking device-code authentication where it is unnecessary. Organisations that require it should restrict access through Conditional Access policies, monitor unusual device registrations and Microsoft Graph activity, and revoke compromised tokens rather than relying on password resets alone.

