EvilTokens Device-Code Phishing Hits 12K Inboxes

About DFIR · High sophistication
Last updated September 25, 2026

Microsoft says it disrupted “EvilTokens,” an AI-powered phishing-as-a-service operation used to break into email accounts at scale. The service automated device-code login phishing end-to-end, helping criminals steal authentication tokens and enable business email compromise across more than 10,000 organizations.

Key findings

  • Microsoft says it disrupted “EvilTokens,” an AI-powered phishing-as-a-service platform tied to threat actor Storm-2992.
  • The operation supported business email compromise and “compromis[ed] more than 12,000 inboxes across over 10,000 organizations worldwide.”
  • The platform “automated the device-code authentication phishing flow end-to-end,” including generating tailored lures and running infrastructure designed to evade detection.
  • Microsoft notes the takedown shows how AI is being “productized” to lower the skill required to run token-theft campaigns.

Who’s being targeted

  • Commonly targeted roles: All staff, Executives and executive assistants, Finance/AP/AR, HR, IT helpdesk, Anyone with access to sensitive email threads.
  • Affected industries: Multiple industries (cross-sector).
  • Attack channels: email, website.
  • Impersonated: Microsoft / Microsoft 365 security or login portal.

Awareness takeaways

  • Treat any unexpected device-code or verification request as suspicious, don’t complete sign-ins you didn’t start.
  • Be cautious of polished, highly tailored emails and login pages, AI can make phishing look legitimate.
  • Assume mailbox compromise is the goal; report quickly because attackers may pivot to fraud (BEC).

Red flags to watch for

  • Unexpected “device code” sign-in request you did not initiate
  • Urgent language pushing immediate action
  • Link leads to an unfamiliar login/verification page
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email: “Action required: complete sign-in using the provided device code.” Looks like Microsoft 365… but it isn’t. This is EvilTokens, an AI-powered phishing service Microsoft just disrupted. It automates a fake device-code login, then steals your authentication token to quietly take over your mailbox. The trick? It looks polished and real, AI-generated emails, AI-generated Microsoft 365 landing pages. But you never started a sign-in, and the link opens an unfamiliar verification site asking for a device code. If you get a device-code or verification email you didn’t trigger, don’t use the code, report it to Security right away so we can stop a mailbox takeover before it becomes fraud.

Similar attacks

EvilTokens MFA Phish Hijacked 12,000 Inboxes

EvilTokens MFA Phish Hijacked 12,000 Inboxes

Microsoft and partners disrupted “EvilTokens,” a phishing service that helped criminals break into more than 12,000 mailboxes across 10,000+ organizations. Victims were tricked into entering an authentication code on a real Microsoft sign-in page, letting attackers capture access tokens and get…

September 23, 2026
EvilTokens Takedown Exposes AI-Driven BEC Fraud

EvilTokens Takedown Exposes AI-Driven BEC Fraud

Microsoft and partners disrupted “EvilTokens,” a phishing-as-a-service operation linked to more than 12,000 compromised Microsoft email inboxes across 10,000+ organizations. The service used AI to pick targets, impersonate trusted contacts, and steal session tokens so criminals could stay in…

September 22, 2026
FBI Warns of OAuth Consent Phishing Tricks

FBI Warns of OAuth Consent Phishing Tricks

A SecurityWeek roundup highlights multiple real-world scams and campaigns where attackers trick people rather than “hack” systems directly. Notable items include OAuth “consent phishing” (getting users to approve a malicious app’s access), and phishing-evasion using invisible Unicode characters…

September 11, 2026
Russian Clusters Hijack Accounts via OAuth & WhatsApp

Russian Clusters Hijack Accounts via OAuth & WhatsApp

Google says multiple suspected Russia-linked espionage clusters targeted academics, government, and defense-related personnel by abusing legitimate sign-in features instead of using obvious fake login pages. The campaigns used realistic lures (file sharing, conference invites, and “secure WhatsApp”…

August 20, 2026
QR-PDF Phishing Hits M365, MFA Bypass Surges

QR-PDF Phishing Hits M365, MFA Bypass Surges

Cisco Talos Incident Response reports that phishing drove initial access in over half of Q2 2026 cases, often using QR codes in PDF attachments and trusted cloud hosting to evade email defenses. Attackers frequently bypassed multi-factor authentication using adversary-in-the-middle proxies,…

July 28, 2026
Microsoft Disrupts EvilTokens Device-Code Phishing

Microsoft Disrupts EvilTokens Device-Code Phishing

Microsoft says it disrupted “EvilTokens,” an AI-assisted phishing service used to trick employees into authorizing attacker access via the device-code login flow (often used for TVs/printers). Victims who entered an attacker-provided code in their browser unknowingly granted access tokens that…

September 23, 2026