EvilTokens Used AI to Supercharge Phishing Scams

The Record · High sophistication
Last updated September 22, 2026

Microsoft and UK police took down “EvilTokens,” an AI-powered phishing service sold on Telegram that helped criminals compromise email accounts and then rapidly find the best ways to commit fraud. The service could analyze a victim’s inbox to identify trusted relationships and financial workflows, then recommend impersonation messages and fraud strategies. A key tactic highlighted was “device code phishing,” where victims enter a short code that unknowingly authorizes an attacker session without sharing a password.

Key findings

  • EvilTokens was sold on Telegram and marketed as an AI-enabled phishing and fraud platform that helped criminals compromise accounts and monetize access.
  • It helped attackers analyze breached inboxes to identify “trusted relationships,” financial conversations, and “money movers,” then recommend who to impersonate and what to say.
  • Victims were lured with themed emails (e.g., invoices and file-sharing requests) containing malicious URLs and attachments, using pre-built phishing templates and landing pages.
  • A widely used method was “device code phishing,” where victims are tricked into entering a code that authorizes the attacker’s session without providing a password.
  • Microsoft said the platform was linked to more than 12,000 compromised inboxes across 10,000+ organizations worldwide and was disrupted via domain and website seizures plus arrests in the UK.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance and Accounts Payable, Executives and executive assistants, IT helpdesk/IT support, Employees who use conferencing/Teams devices.
  • Affected industries: Cross-industry (multiple sectors across 10,000+ organizations).
  • Attack channels: email, website.
  • Impersonated: A vendor, partner, or trusted contact, A legitimate sign-in flow for a device/app (e.g., smart TV, printer, conferencing tool, Teams device).

Awareness takeaways

  • Treat unexpected invoice and file-sharing emails as high-risk and verify using a known, trusted contact method before clicking links or opening attachments.
  • If you receive a login/device code you didn’t request, do not enter it anywhere, report it as a likely takeover attempt.
  • Don’t assume ‘no password asked’ means it’s safe, attackers can gain access by tricking you into approving their session.
  • Be extra cautious with requests involving payments, vendor invoices, and approvals; attackers may impersonate trusted contacts based on what they find in inbox conversations.

Red flags to watch for

  • Unexpected invoice or file-sharing request
  • Link/attachment is unnecessary or unusual for the sender’s normal process
  • Message pressures quick review/action despite limited context
  • You did not initiate a device sign-in, but you received a code anyway
  • The request claims you can approve access without logging in normally
  • The sign-in is tied to an unfamiliar device or vague prompt
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Microsoft just helped take down an AI phishing service called EvilTokens that hit over ten thousand organizations. EvilTokens scanned stolen inboxes, spotted who moves money, then sent perfect fake invoices and file‑sharing emails that looked exactly like your vendor or partner. Here’s the sneaky part: device code phishing. You get an email with a short sign‑in code and a link. You type it in, no password asked, and you’ve just approved the criminal’s session into your account. If you ever get a device or login code you didn’t start, stop and report it to IT immediately, do not enter that code anywhere.

Similar attacks

EvilTokens Takedown Exposes AI-Driven BEC Fraud

EvilTokens Takedown Exposes AI-Driven BEC Fraud

Microsoft and partners disrupted “EvilTokens,” a phishing-as-a-service operation linked to more than 12,000 compromised Microsoft email inboxes across 10,000+ organizations. The service used AI to pick targets, impersonate trusted contacts, and steal session tokens so criminals could stay in…

September 22, 2026
EvilTokens MFA Phish Hijacked 12,000 Inboxes

EvilTokens MFA Phish Hijacked 12,000 Inboxes

Microsoft and partners disrupted “EvilTokens,” a phishing service that helped criminals break into more than 12,000 mailboxes across 10,000+ organizations. Victims were tricked into entering an authentication code on a real Microsoft sign-in page, letting attackers capture access tokens and get…

September 23, 2026
Device-Code Phishing Service Hit After 12K Breaches

Device-Code Phishing Service Hit After 12K Breaches

Microsoft and partners disrupted “EvilTokens,” a phishing-as-a-service platform Microsoft links to over 12,000 compromised inboxes across more than 10,000 organizations. The service used deceptive emails to trick people into pasting a “device code” into Microsoft’s real sign-in page…

September 22, 2026
Microsoft Disrupts EvilTokens Device-Code Phishing

Microsoft Disrupts EvilTokens Device-Code Phishing

Microsoft says it disrupted “EvilTokens,” an AI-assisted phishing service used to trick employees into authorizing attacker access via the device-code login flow (often used for TVs/printers). Victims who entered an attacker-provided code in their browser unknowingly granted access tokens that…

September 23, 2026
EvilTokens Device-Code Phish Hit 12,000 Inboxes

EvilTokens Device-Code Phish Hit 12,000 Inboxes

EvilTokens was a phishing-as-a-service operation that used “device code phishing” to trick employees into authorizing an attacker session on Microsoft’s real login infrastructure, often bypassing MFA without stealing passwords. After access, attackers used AI to find payment-related conversations…

September 23, 2026
Phishers Abuse DocuSign, Rewards, and “Verification”

Phishers Abuse DocuSign, Rewards, and “Verification”

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials or install remote-control tools. The common theme is trust abuse: messages and web pages look legitimate, then push users to log in, click…

July 28, 2026