Microsoft Disrupts ‘EvilTokens’ Phishing Service

IT Pro Security · High sophistication
Last updated September 24, 2026

Microsoft says it disrupted the “EvilTokens” phishing-as-a-service platform, which it links to compromises of over 12,000 inboxes across more than 10,000 organizations. The service used AI to tailor phishing emails to a victim’s role and to analyze compromised inboxes to identify trusted relationships and the best opportunities for payment fraud. Microsoft and partners seized associated websites/domains, and UK police arrested two suspects.

How the Attack Worked

EvilTokens operated as a phishing-as-a-service platform. Subscribers could generate personalized lures using AI that tailored phishing emails to a target's specific role, rather than sending generic messages to everyone. Microsoft found that common themes used to increase response rates included document signing services, cloud identity, file hosting, payment or invoicing, voicemail, and eFax notifications. Each of these themes was designed to feel routine enough that an employee would click without hesitation.

Beyond the initial lure, the service included an AI-style chatbot capable of analyzing a victim's inbox once access was gained. This chatbot could identify trusted relationships, payment authorizations, and sensitive responsibilities within the mailbox, then recommend strategies for carrying out fraud. This included drafting messages that impersonated trusted contacts, turning a single compromised inbox into a launchpad for further attacks against the victim's real business relationships.

Why It Succeeded

The effectiveness of EvilTokens came from combining role-specific targeting with post-compromise intelligence. A generic phishing email is easier to spot, but a message referencing a document signing service or an invoicing platform that matches an employee's actual job function is far more believable. Once inside an inbox, the chatbot's ability to map trusted relationships meant follow-on fraud attempts could closely mimic real communication patterns, making them harder to distinguish from legitimate requests.

What to Watch For

  • Unexpected requests to sign a document, especially when you weren't expecting one
  • Voicemail or eFax notification emails that ask you to log in to view a basic message
  • Payment or invoice requests tied to unusual changes, such as a new account or rushed timing
  • Sender or reply-to details that don't match the known contact, even if the message content looks familiar
  • Messages that create urgency to bypass normal verification steps

How to Build Resistance

Organizations can reduce exposure to this kind of AI-assisted phishing and business email compromise by reinforcing a few habits across roles most likely to be targeted, including finance, procurement, executive assistants, and HR:

  • Verify unexpected document-signing or service notifications through a separate, known channel before clicking any link
  • Treat any payment or invoice change request as suspicious until confirmed independently, since attackers may impersonate real trusted contacts using information from a compromised inbox
  • Recognize that phishing content may be tailored specifically to your job function, so generic red flags alone are not sufficient
  • Encourage reporting of unusual sign-in prompts tied to voicemail, eFax, or document services, since these were common lure themes in this campaign

Key findings

  • Microsoft says EvilTokens was used to compromise “more than 12,000 inboxes at more than 10,000 organizations.”
  • The platform offered “AI [to] create targeted phishing emails that were specifically aligned to the target’s role.”
  • Microsoft said lures commonly referenced “document signing services,” “cloud identity,” “file hosting,” “payment or invoicing,” “voicemail,” and “eFax.”
  • The service included an AI-style chatbot that could “analyze a victim’s inbox” to identify “trusted relationships” and “payment authorizations,” and then recommend impersonation-based fraud strategies.
  • Microsoft reported seizing “50 websites” and “more than 150 other domains” tied to the infrastructure; UK police arrested two suspects.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance / Accounts Payable, Procurement, Executive assistants, HR, Sales, IT / Security teams.
  • Affected industries: Wholesale distribution, Construction, Financial services, Real estate, Higher education, Healthcare.
  • Attack channels: email.
  • Impersonated: Document signing service / cloud service provider, Voicemail or eFax service, Trusted vendor/customer/internal contact.

Red flags to watch for

  • Unexpected signature request you weren’t expecting
  • Link leads to a credential capture page (not the normal service URL)
  • Message urgency that pressures immediate action
  • You don’t normally receive voicemail/eFax notifications via email
  • Link/branding doesn’t match your organization’s real provider
  • Request to sign in to view a basic voicemail/fax
  • Payment request tied to an unusual change (new account, new process, rushed timing)
  • Reply-to or sender details don’t match the known contact
  • Request bypasses normal approval steps
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What was the EvilTokens phishing service?

EvilTokens was a phishing-as-a-service platform that Microsoft says was linked to compromises of more than 12,000 inboxes at more than 10,000 organizations. It used AI to craft targeted phishing emails and analyze compromised inboxes for fraud opportunities.

What lures did EvilTokens use to trick victims?

Common themes included document signing services, cloud identity, file hosting, payment or invoicing, voicemail, and eFax notifications, all designed to prompt a login or click.

How did the AI chatbot help attackers commit fraud?

The chatbot could analyze a victim's inbox to identify trusted relationships, payment authorizations, and sensitive responsibilities, then recommend impersonation strategies to draft convincing fraud messages.

What happened to the infrastructure behind EvilTokens?

Microsoft reported seizing 50 websites and more than 150 other domains tied to the service, and UK police arrested two suspects.

Read the video transcript

Imagine a phishing email that already knows your job, your vendors, even how you approve payments. That’s EvilTokens. Microsoft just disrupted EvilTokens after it helped break into over twelve thousand inboxes. It used AI to write role-specific lures like fake document-signing, cloud login, payment, voicemail, or eFax emails, then analyzed inboxes to spot trusted relationships and payment approvals. Here’s the trick: you get an email, 'Document signature required' or 'New voicemail/eFax received, view message.' You click, land on a page asking for your Microsoft 365 login. The logo looks right, but the URL isn’t your usual document-signing, voicemail, or eFax provider. That page is just there to steal your credentials. Your move: if you get an unexpected document-sign, voicemail, eFax, or payment email, don’t click the link, go to the service or contact the person through a known channel and verify it first.

Similar attacks

EvilTokens Uses Device Codes to Bypass MFA

EvilTokens Uses Device Codes to Bypass MFA

Microsoft reports that the EvilTokens phishing-as-a-service platform helped criminals compromise thousands of organizations by tricking users into completing a legitimate Microsoft “device code” login. The lure drives victims to enter a short code at microsoft.com/devicelogin, which unknowingly…

September 22, 2026
Phishing Link Could Plant a Rogue ChatGPT Agent

Phishing Link Could Plant a Rogue ChatGPT Agent

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled Workspace Agent inside a company. If an employee was already logged in and had connected apps (like email, Drive, Slack, or Teams), the agent…

July 24, 2026
EvilTokens Device-Code Phish Hit 12,000 Inboxes

EvilTokens Device-Code Phish Hit 12,000 Inboxes

EvilTokens was a phishing-as-a-service operation that used “device code phishing” to trick employees into authorizing an attacker session on Microsoft’s real login infrastructure, often bypassing MFA without stealing passwords. After access, attackers used AI to find payment-related conversations…

September 23, 2026
Phishers Abuse DocuSign, Rewards, and “Verification”

Phishers Abuse DocuSign, Rewards, and “Verification”

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials or install remote-control tools. The common theme is trust abuse: messages and web pages look legitimate, then push users to log in, click…

July 28, 2026
EvilTokens Used Device-Code Phish to Fuel BEC

EvilTokens Used Device-Code Phish to Fuel BEC

Microsoft disrupted “EvilTokens,” a subscription cybercrime service that stole Microsoft account access using device-code phishing and then used AI-style automation to rapidly mine victims’ inboxes for payment and org-chart details. The goal was to quickly craft believable payment-fraud messages…

September 23, 2026
Fake AI Trading Bot Steals Crypto Wallet Passwords

Fake AI Trading Bot Steals Crypto Wallet Passwords

Researchers observed real campaigns where a fake “AI crypto trading agent” website tricked victims into downloading malware that silently replaces browser wallet extensions and steals the wallet password when it’s typed. The same reporting also describes invoice emails using QR codes to push…

September 17, 2026