Microsoft Disrupts EvilTokens Phishing Service Linked to 12,000+ Compromised Inboxes

Microsoft has taken down EvilTokens, an AI-powered phishing-as-a-service (PhaaS) platform linked to more than 12,000 compromised email inboxes across 10,000+ organizations worldwide.

The platform exploited Microsoft's *device code authentication flow to trick users into approving attacker-controlled sessions—often without directly stealing their passwords. Once access was obtained, attackers could read emails, create malicious inbox rules, maintain persistence, and identify opportunities for financial fraud.

Fake Claude Code Installer Spreads Fileless .NET Infostealer via SEO PoisoningFake Claude Code Installer Spreads Fileless .NET Infostealer via SEO Poisoning

EvilTokens also used AI to analyze compromised mailboxes, identify sensitive conversations and trusted contacts, and help criminals create convincing impersonation emails. This significantly reduced the technical expertise required to conduct business email compromise (BEC) and invoice fraud.

Microsoft worked with organizations including Cloudflare, Coinbase, OpenAI, SpyCloud, and others to disrupt the infrastructure. Authorities also arrested two individuals allegedly connected to the operation.

The incident highlights how AI is making phishing and social engineering attacks more scalable and convincing. Users should be cautious when asked to enter authentication codes, even when the verification page appears to be a legitimate Microsoft website.

A legitimate login page can still be part of a phishing attack. Never enter a device code or approve a sign-in you didn’t initiate. Keep your security software updated, stay alert to unexpected login requests, and protect every layer of your digital activity with Net Protector Total Security.