Device-Code Phishing Service Hit After 12K Breaches

The Hacker News · High sophistication
Last updated September 22, 2026

Microsoft and partners disrupted “EvilTokens,” a phishing-as-a-service platform Microsoft links to over 12,000 compromised inboxes across more than 10,000 organizations. The service used deceptive emails to trick people into pasting a “device code” into Microsoft’s real sign-in page (microsoft.com/devicelogin), which granted attackers ongoing access without stealing a password. The platform also used AI to read stolen mailboxes and draft convincing impersonation messages aimed at fraud and invoice scams.

Key findings

  • Microsoft attributes EvilTokens development/support to “Storm-2992.”
  • EvilTokens abused the OAuth 2.0 device authorization flow to obtain access/refresh tokens and keep access without needing the victim’s password.
  • Lures commonly used business themes (invoices, RFPs, shared files) and drove victims to enter a device code on the legitimate microsoft.com/devicelogin page.
  • The service used AI to analyze compromised inboxes, identify trusted relationships and payment authority, and draft impersonation messages for fraud.
  • Microsoft linked EvilTokens to “more than 12,000 compromised email inboxes across over 10,000 organizations worldwide.”
  • Attackers used multi-stage redirection, fake CAPTCHA checks, and serverless hosting (e.g., Vercel, Cloudflare Workers, AWS Lambda) to evade defenses.

Who’s being targeted

  • Commonly targeted roles: All employees (Microsoft 365 users), Finance & Accounts Payable, Procurement/Vendor management, Executives and executive assistants, IT helpdesk/support staff.
  • Affected industries: Wholesale distribution, Construction, Financial services, Real estate, Higher education, Healthcare.
  • Attack channels: email, website.
  • Impersonated: A vendor/business partner (invoice/RFP) or shared-file sender, Microsoft sign-in workflow (via a lookalike flow that forwards to the real portal).

Awareness takeaways

  • Treat any request to copy/paste a “device code” into microsoft.com/devicelogin as a high-risk sign-in scam unless you personally initiated the device setup.
  • Be extra cautious with invoice/RFP/shared-file emails, these are common themes used to get clicks and start the takeover chain.
  • Password resets alone may not stop an account takeover, security teams must revoke sessions/tokens when compromise is suspected.
  • If you get an unexpected MFA prompt after clicking a link, stop and report it, this may mean someone is trying to log in as you.

Red flags to watch for

  • Unexpected request to enter a “device code” to view an invoice/RFP/shared file
  • Being pushed to complete sign-in steps that benefit someone else (copy/paste code)
  • Extra redirects/fake CAPTCHA steps before reaching Microsoft
  • A third-party page generating a “live device code” before sending you to Microsoft
  • You are asked to paste a code into a sign-in flow not initiated by you
  • MFA prompt appears unexpectedly after clicking an email link
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine this: you’re on the real microsoft.com/devicelogin page… and you’re still getting scammed. Storm-2992’s EvilTokens sends a fake invoice or RFP email, then a web page pops up a “live” device code and a big “Continue with Microsoft” button that walks you to the real Microsoft sign-in while silently handing your mailbox to them. Here’s the trap: you paste that code into microsoft.com/devicelogin, maybe even pass MFA, and EvilTokens gets OAuth tokens that keep reading your email and sending AI-written fake invoices as you, no password needed, even after a reset. If you’re ever asked to copy a device code into microsoft.com/devicelogin for an invoice, RFP, or shared file you didn’t start yourself, stop and report it to security immediately.

Similar attacks

Microsoft Disrupts EvilTokens Device-Code Phishing

Microsoft Disrupts EvilTokens Device-Code Phishing

Microsoft says it disrupted “EvilTokens,” an AI-assisted phishing service used to trick employees into authorizing attacker access via the device-code login flow (often used for TVs/printers). Victims who entered an attacker-provided code in their browser unknowingly granted access tokens that…

September 23, 2026
EvilTokens MFA Phish Hijacked 12,000 Inboxes

EvilTokens MFA Phish Hijacked 12,000 Inboxes

Microsoft and partners disrupted “EvilTokens,” a phishing service that helped criminals break into more than 12,000 mailboxes across 10,000+ organizations. Victims were tricked into entering an authentication code on a real Microsoft sign-in page, letting attackers capture access tokens and get…

September 23, 2026
EvilTokens Device-Code Phish Hit 12,000 Inboxes

EvilTokens Device-Code Phish Hit 12,000 Inboxes

EvilTokens was a phishing-as-a-service operation that used “device code phishing” to trick employees into authorizing an attacker session on Microsoft’s real login infrastructure, often bypassing MFA without stealing passwords. After access, attackers used AI to find payment-related conversations…

September 23, 2026
EvilTokens Takedown Exposes AI-Driven BEC Fraud

EvilTokens Takedown Exposes AI-Driven BEC Fraud

Microsoft and partners disrupted “EvilTokens,” a phishing-as-a-service operation linked to more than 12,000 compromised Microsoft email inboxes across 10,000+ organizations. The service used AI to pick targets, impersonate trusted contacts, and steal session tokens so criminals could stay in…

September 22, 2026
EvilTokens Used AI to Supercharge Phishing Scams

EvilTokens Used AI to Supercharge Phishing Scams

Microsoft and UK police took down “EvilTokens,” an AI-powered phishing service sold on Telegram that helped criminals compromise email accounts and then rapidly find the best ways to commit fraud. The service could analyze a victim’s inbox to identify trusted relationships and financial workflows,…

September 22, 2026
EvilTokens Uses Device Codes to Bypass MFA

EvilTokens Uses Device Codes to Bypass MFA

Microsoft reports that the EvilTokens phishing-as-a-service platform helped criminals compromise thousands of organizations by tricking users into completing a legitimate Microsoft “device code” login. The lure drives victims to enter a short code at microsoft.com/devicelogin, which unknowingly…

September 22, 2026