Trusence Technology, daily
Last updated 24 September 2026 Türkçe
← All stories
Security

Microsoft and partners disrupt EvilTokens phishing service after 12,000 account breaches

The takedown hits a service that automated device-code phishing at scale, largely against enterprise Microsoft accounts worldwide.

Microsoft’s Digital Crimes Unit and partners including Health-ISAC, law enforcement, and SpyCloud disrupted EvilTokens, a phishing-as-a-service platform that abused Microsoft’s OAuth 2.0 device-code flow to breach over 12,000 accounts in more than 10,000 organizations. Launched in February and sold via Telegram for a $1,500 setup fee plus $500 per month, EvilTokens automated device-code phishing, bypassing MFA and targeting sectors such as financial services, construction, higher education, and healthcare. The service bundled 44 phishing kits, add-on tools (like anti-bot redirectors and Office 365 capture links), and AI features that used Microsoft Graph data and inbox content to find high-value targets and generate tailored BEC emails. SpyCloud telemetry shows the operation was overwhelmingly focused on corporate victims, with about 97.5% of stolen accounts tied to enterprise domains across at least 79 countries. Authorities in the U.K. arrested two suspected administrators and seized active infrastructure, but Microsoft cautions that EvilTokens and copycats such as APToken are still active, so organizations should disable unnecessary device-code auth and adopt phishing-resistant methods like FIDO2 keys or passkeys.

Why it matters

The disruption of EvilTokens removes a service that made it easier for attackers to bypass multi-factor authentication on Microsoft accounts and focus on corporate targets. With more than 12,000 inboxes across over 10,000 organizations compromised and about 97.5% of victims tied to enterprise domains in dozens of countries, the operation shows how phishing-as-a-service can industrialize business email compromise and reach sectors from finance and healthcare to higher education before law enforcement steps in.

Sources