EvilTokens phishing abused the OAuth 2.0 device authorization flow. Victims completed a real Microsoft sign-in and MFA prompt, so attackers never needed a password.
Microsoft tied the service to over 12,000 compromised inboxes across more than 10,000 organizations, with an AI chatbot that scanned mailboxes to find fraud opportunities and draft impersonation messages.
Microsoft tracks the operators as Storm-2992. The Metropolitan Police Service arrested two men, aged 32 and 38, on September 11, 2026, following a joint takedown with eight industry and nonprofit partners.
Stolen tokens can grant new device access and support persistence. That access can survive a password reset if the associated sessions and tokens stay active.
Microsoft disrupted the EvilTokens phishing service on September 22, 2026. The takedown targeted a device-code phishing platform that Microsoft says used AI “at every step of the attack chain.” EvilTokens did not steal passwords. It abused a legitimate Microsoft sign-in mechanism to obtain live authentication tokens.
The service combined OAuth token theft with an AI mailbox analysis tool. That tool read compromised inboxes, found lucrative conversations, and drafted impersonation emails. Microsoft linked EvilTokens phishing activity to more than 12,000 compromised inboxes across over 10,000 organizations worldwide.
The action involved Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs. It proceeded under authorization from the U.S. District Court for the Eastern District of Virginia.
How the device-code lure works
EvilTokens phishing relied on a technique separate from ordinary credential harvesting. It exploited Microsoft’s device authorization flow, a legitimate feature built for devices without a browser or keyboard.
The attack unfolded in distinct steps, and each step served a different purpose:
A phishing email, built from one of 44 lure themes such as invoices or shared files, delivered a malicious link or attachment.
Clicking it launched a background script that requested a live device code from Microsoft’s identity service, using the Client ID of a legitimate first-party Microsoft app, commonly Microsoft Office’s own Client ID.
The page displayed that code and a “Continue with Microsoft” button, which routed the victim to the real microsoft.com/devicelogin page.
The victim entered the code and, if needed, their password and MFA code on Microsoft’s own site.
Once entered, Microsoft’s authorization server issued access and refresh tokens for that Client ID. Only the attacker’s script, which had initiated the original request and held the matching device code, could poll for and receive those tokens.
That last step is the mechanism that matters most. The victim’s code entry only completes the sign-in. Whoever holds the device code from the original request is the one who receives the resulting tokens, regardless of who the Client ID belongs to.
What is Threat Analysis?
A beginner's guide to threat analysis, correlation, and Hexnode XDR's investigative capabilities.
An AI engine built for fraud, not just access
Getting into an inbox was only the first half of the EvilTokens phishing platform. Sekoia reported in March 2026 that the service sold itself on Telegram as a turnkey phishing-as-a-service platform, with AI features added to automate business email compromise workflows.
Its AI-style tooling let paying customers do the following:
Automated multilingual thread hijacking. The AI reads and responds inside compromised mailboxes in more than twenty languages, per SpyCloud, so attackers run BEC scams in the victim’s own language without speaking a word of it themselves.
Money-mover targeting. The AI maps organizational roles to flag exactly who can approve or release a payment, skipping the manual reconnaissance BEC actors used to do by hand.
Live invoice hijacking. The AI surfaces active wire-transfer and vendor invoice threads, letting attackers insert themselves into a payment conversation already in motion instead of starting one from scratch.
Impersonation-ready fraud drafts. The AI writes messages that mimic a trusted contact, engineered to redirect a real payment to an account the attacker controls.
Steven Masada, Microsoft’s Digital Crimes Unit general manager, said the platform could recommend fraud strategies once account access was established. This is why the case matters for identity security teams. It is not just Microsoft 365 account takeover. It is automated fraud preparation running immediately after token theft.
The scale and reach
Attack Stage
What Happens
Operational Risk
Device code lure
Victim enters a real code on Microsoft’s sign-in page
Bypasses password-focused phishing filters
Token issuance
Access and refresh tokens go to the attacker’s client
Grants MFA bypass without credential theft
Inbox persistence
Malicious rules and new device registrations get added
Survives password resets if unaddressed
AI mailbox triage
Finance threads and trusted contacts get flagged automatically
Speeds up business email compromise at scale
Coinbase traced roughly $1.1 million in EvilTokens revenue across four Tron addresses between October 2025 and June 2026. SpyCloud separately recaptured 8,708 unique victim accounts spanning 6,585 corporate domains in 79 countries, with the earliest captures dating to February 18, 2026.
Attribution and the takedown
Microsoft tracks the developers and operators behind EvilTokens as Storm-2992. The Metropolitan Police Service arrested two men, aged 32 and 38, on September 11, 2026, in connection with the operation.
The joint action seized 50 websites tied to the service and disabled more than 150 supporting domains. TRM Labs noted that EvilTokens lowered the skill barrier for running business email compromise, since it packaged account access, AI analysis, and fraud tooling into one subscription product.
Why token theft outlives a password reset
Microsoft made a specific point in its disclosure. Victims can reset a compromised password and remain exposed. If the attacker’s sessions and tokens stay active, access continues unaffected.
Security teams should treat token and session revocation as a separate, mandatory step. Password resets alone do not close this gap.
Featured resource
Cybersecurity kit
Free cybersecurity kit: blueprint, framework guide, IT checklist, incident policy template, UEM infographic, and management guides.
Hexnode offers three products relevant here: IdP, UEM, and XDR. Each covers a different part of the gap.
Hexnode IdP can automate token and session revocation for apps under its control, using SAML and OIDC for SSO plus SCIM 2.0 for account lifecycle management.
Deactivating a user terminates all active sessions instantly.
The same action revokes all refresh and access tokens for that user.
SCIM then pushes deactivation to every connected app on the next sync.
This closes the reset-doesn’t-help gap only for apps provisioned through Hexnode IdP’s SCIM integration. If Microsoft 365 is the organization’s identity source, as in most EvilTokens cases, Microsoft’s own admin console remains the place to revoke those tokens.
Hexnode UEM restricts access from unmanaged or non-compliant devices through Conditional Access integration with Microsoft Entra ID.
Reports device compliance to Entra ID for Android, iOS, and macOS only.
Blocks non-compliant or unmanaged devices on these platforms from accessing resources.
Narrows the pool of unmanaged devices an attacker could register during persistence.
Hexnode XDR adds a separate layer of visibility, though its scope is limited.
Currently supports Windows and macOS endpoints.
Its Incidents tab flags identity-provider sync issues, like failed AD syncs or deleted directory objects.
Does not detect EvilTokens phishing, analyze OAuth token abuse, or correlate findings from external identity tools.
Does resetting a password stop EvilTokens phishing access?
Not on its own. Microsoft confirmed that access can persist unless the associated sessions and refresh tokens are also revoked.
How is device-code phishing different from typical credential phishing?
The victim authenticates on Microsoft’s real sign-in page. The attacker’s client receives the resulting tokens instead of the victim ever handing over a password.
What should security teams check first if EvilTokens activity is suspected?
Review sign-in logs for device-code grants, audit inbox rules for unfamiliar forwarding, and revoke suspicious sessions and tokens immediately.
Conclusion
EvilTokens phishing shows how a legitimate authentication flow can become a full account takeover and fraud pipeline. The service paired OAuth token theft with AI-driven mailbox analysis to scale business email compromise well beyond what manual attackers could achieve.
Enterprises should monitor device-code sign-in activity, revoke tokens and sessions during incident response, and pair identity controls with device-aware access policies.
Stop token theft before it spreads.
See how device-aware access controls reduce identity attack exposure across your fleet.
A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions—without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable—politely.