EvilTokens MFA Phish Hijacked 12,000 Inboxes

Help Net Security · High sophistication
Last updated September 24, 2026

Microsoft and partners disrupted “EvilTokens,” a phishing service that helped criminals break into more than 12,000 mailboxes across 10,000+ organizations. Victims were tricked into entering an authentication code on a real Microsoft sign-in page, letting attackers capture access tokens and get into inboxes without stealing passwords. Once inside, an AI chatbot analyzed emails to identify finance workflows and the best people to impersonate for fraud.

How the Attack Worked

EvilTokens operated as a phishing service that compromised more than 12,000 inboxes at over 10,000 organizations. Rather than stealing passwords outright, the scheme relied on tricking victims into entering an authentication code on Microsoft's legitimate sign-in page. By completing what looked like a routine MFA step, victims unknowingly handed over access tokens and sessions to attackers, all without ever revealing their actual password.

Once inside a mailbox, the service reportedly included an AI chatbot capable of summarizing and translating emails, identifying financial conversations, mapping organizational roles, and suggesting the best people to impersonate. Preset prompts were built around fraud enablement, such as locating wire transfer discussions, vendor invoices, and an organization's 'money movers.'

Why It Succeeded

The technique succeeded because it exploited a step users are trained to trust: entering a code on a real sign-in page. Because the phishing flow used Microsoft's legitimate authentication page, there was no obviously fake login form to spot. This let attackers capture session tokens directly, sidestepping the need to guess or steal a password at all.

The persistence of this access compounds the problem. Access could persist even after a password reset if the associated sessions and tokens were not also revoked, meaning standard credential-reset procedures alone were not sufficient to remove an attacker from a compromised account.

What to Watch For

  • Unexpected 'security alert' messages asking a user to confirm or enter an authentication code
  • Pressure or urgency to act immediately on a sign-in notification the user did not initiate
  • Links in email that lead to a sign-in page, rather than navigating there directly
  • Payment change requests arriving only by email, especially involving vendor invoices or wire transfers
  • Bank detail changes that have not been verified through a separate, trusted channel

Building Resistance

Organizations should treat unexpected authentication code prompts as high risk and avoid entering codes triggered by an email link, navigating to sign-in pages directly instead. Because compromised inboxes can be understood by attackers within minutes, incident response should move quickly and include full session and token revocation, not just a password reset.

Finance, accounts payable, and procurement staff should independently verify requests to change payment information, redirect funds, or approve unusual transactions through a trusted second channel, regardless of how legitimate the email thread appears. Building this verification habit reduces the payoff for attackers even if an inbox is compromised.

Key findings

  • EvilTokens compromised “more than 12,000 inboxes at over 10,000 organizations.”
  • Victims were “tricked into entering an authentication code on Microsoft’s legitimate sign-in page,” enabling access without stealing passwords.
  • Access could persist “even after a password reset if the associated sessions and tokens were not also revoked.”
  • An AI chatbot inside the service could summarize and translate emails, identify financial conversations, map roles, and suggest “the best people to impersonate.”
  • Preset prompts focused on fraud enablement (e.g., wire transfers, vendor invoices, identifying “money movers”).
  • Microsoft and partners seized “50 websites” and disabled “more than 150 domains” supporting the service.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance/AP, Procurement, IT helpdesk / Identity & Access Management, Security Operations / Incident Response.
  • Affected industries: Wholesale distribution, Construction, Financial services, Higher education, Healthcare.
  • Attack channels: email, website.
  • Impersonated: Microsoft (account security / sign-in), Trusted contact inside the victim’s email threads (vendor/customer/colleague).

Red flags to watch for

  • A request to enter/share an authentication code in response to an unexpected message
  • Pressure/urgency to act immediately on a sign-in alert you didn’t initiate
  • Following a link from an email instead of navigating to the sign-in page directly
  • Payment change requests that arrive only by email
  • Unusual urgency or secrecy around payment updates
  • Bank detail changes that aren’t verified via a known second channel
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What was EvilTokens?

EvilTokens was a phishing service disrupted by Microsoft and partners that compromised more than 12,000 inboxes at over 10,000 organizations by capturing authentication codes and tokens instead of passwords.

How did EvilTokens bypass MFA without stealing passwords?

Victims were tricked into entering an authentication code on Microsoft's legitimate sign-in page, which handed over access tokens and sessions to attackers without ever exposing the actual password.

Does resetting a password stop this kind of attack?

Not necessarily. Access could persist even after a password reset if the associated sessions and tokens were not also revoked.

How did attackers use compromised inboxes for fraud?

An AI chatbot inside the service analyzed emails to find wire transfer discussions, vendor invoices, and 'money movers,' then suggested the best contacts to impersonate for payment fraud.

Read the video transcript

EvilTokens hijacked over twelve thousand inboxes by abusing one thing we trust most: our MFA code. You click, land on the real Microsoft sign-in page, and type the authentication code to 'stop' the attack. That normal step silently hands over access tokens, so they get into your mailbox without ever knowing your password, and can stay in even after a password reset. Inside your inbox, EvilTokens used an AI chatbot to summarize threads, find wire transfers, vendor invoices, and your 'money movers,' then draft emails that sound exactly like your colleagues: 'Hi, we need to update payment details for the next invoice…' Your move: if you ever get a surprise Microsoft security alert asking for a code, don’t enter it from that email. Close it, go to portal.office.com or microsoft365.com yourself, and handle sign-in and codes only there.

Similar attacks

Microsoft Disrupts EvilTokens Device-Code Phishing

Microsoft Disrupts EvilTokens Device-Code Phishing

Microsoft says it disrupted “EvilTokens,” an AI-assisted phishing service used to trick employees into authorizing attacker access via the device-code login flow (often used for TVs/printers). Victims who entered an attacker-provided code in their browser unknowingly granted access tokens that…

September 23, 2026
Device-Code Phishing Service Hit After 12K Breaches

Device-Code Phishing Service Hit After 12K Breaches

Microsoft and partners disrupted “EvilTokens,” a phishing-as-a-service platform Microsoft links to over 12,000 compromised inboxes across more than 10,000 organizations. The service used deceptive emails to trick people into pasting a “device code” into Microsoft’s real sign-in page…

September 22, 2026
EvilTokens Takedown Exposes AI-Driven BEC Fraud

EvilTokens Takedown Exposes AI-Driven BEC Fraud

Microsoft and partners disrupted “EvilTokens,” a phishing-as-a-service operation linked to more than 12,000 compromised Microsoft email inboxes across 10,000+ organizations. The service used AI to pick targets, impersonate trusted contacts, and steal session tokens so criminals could stay in…

September 22, 2026
EvilTokens Device-Code Phish Hit 12,000 Inboxes

EvilTokens Device-Code Phish Hit 12,000 Inboxes

EvilTokens was a phishing-as-a-service operation that used “device code phishing” to trick employees into authorizing an attacker session on Microsoft’s real login infrastructure, often bypassing MFA without stealing passwords. After access, attackers used AI to find payment-related conversations…

September 23, 2026
EvilTokens Used AI to Supercharge Phishing Scams

EvilTokens Used AI to Supercharge Phishing Scams

Microsoft and UK police took down “EvilTokens,” an AI-powered phishing service sold on Telegram that helped criminals compromise email accounts and then rapidly find the best ways to commit fraud. The service could analyze a victim’s inbox to identify trusted relationships and financial workflows,…

September 22, 2026
FBI Warns of OAuth Consent Phishing Tricks

FBI Warns of OAuth Consent Phishing Tricks

A SecurityWeek roundup highlights multiple real-world scams and campaigns where attackers trick people rather than “hack” systems directly. Notable items include OAuth “consent phishing” (getting users to approve a malicious app’s access), and phishing-evasion using invisible Unicode characters…

September 11, 2026