Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Trump follows in Hugo Chavez’s footsteps to launch his own TV channel | Media News

    September 22, 2026

    Ed Davey promises tax cuts for millions if UK rejoins EU single market

    September 22, 2026

    Call of Duty’s Activision to make next Halo game as Xbox cuts more jobs

    September 22, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Trump follows in Hugo Chavez’s footsteps to launch his own TV channel | Media News
    • Ed Davey promises tax cuts for millions if UK rejoins EU single market
    • Call of Duty’s Activision to make next Halo game as Xbox cuts more jobs
    • Cyera Raises $400 Million at $12+ Billion Valuation
    • No Bitcoin Payments In Russia — But The Digital Ruble Is Open For Business
    • Can AI reason without words? A small model puts the idea to the test
    • Photographing Sri Lanka’s human-elephant conflict — Interview with Federico Borella
    • QatarEnergy’s CEO: Repairs on damaged LNG trains to take three years
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, September 22
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 22, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft’s Digital Crimes Unit (DCU).

    The phishing-as-a-service (PhaaS) operation emerged in February and was the first to support device code authentication at scale and offer cybercriminals AI-powered features for customizing lures and sifting through compromised inboxes to identify high-value targets.

    In an announcement today, Microsoft said it coordinated the takedown of EvilTokens’ infrastructure, an action that involved the Health-ISAC, law enforcement, and SpyCloud, an identity threat protection company based in Austin, Texas.

    Following the investigation, two men, aged 32 and 38, suspected of being administrators of the EvilTokens website were arrested in the U.K.

    The Metropolitan Police Service received information about the suspects in August and executed warrants on Friday at addresses in Canary Wharf and Nine Elms. Both suspects were released on bail pending further investigation.

    “The Met remains committed to holding people to account who facilitate criminal enabling functions and think they can remain undetected. We will find you and take action,” Detective Inspector Serena D’Adamo told BleepingComputer.

    Microsoft tracks the EvilTokens threat actor as Storm-2992, stating that campaigns using the PhaaS platform impacted organizations in wholesale distribution, construction, financial services, real estate, higher education, and healthcare sectors.

    The researchers say that the cybercriminal service specializes in device-code phishing, a technique that abuses the device-code authentication flow to obtain authentication tokens despite MFA protections, allowing attackers to compromise accounts without needing credential theft.

    This led to a surge in device code phishing this year as multiple threat actors have adopted the method. By April, there were at least 10 phishing platforms supporting the capability.

    Microsoft says in a report today that EvilTokens compromised more than 12,000 inboxes across over 10,000 organizations worldwide, fueling “sophisticated business email compromise (BEC) campaigns.”

    SpyCloud’s recaptured phished data shows more than 8,708 compromised accounts across 6,585 corporate email domains in 79 countries.

    EvilTokens abuses Microsoft’s legitimate OAuth 2.0 device-authorization flow, which is designed for devices with limited input capabilities, such as smart TVs, printers, conferencing equipment, and some Teams devices.

    Generated code
    Generated code
    Source: Microsoft

    A device code phishing attack starts with the attacker initiating a device-code request and sending the received code to a target as part of a phishing lure.

    The victim is directed to a page that displays the code and a button that links to Microsoft’s legitimate login portal, where they are prompted to authenticate.

    Storm-2992 promoted and supported EvilTokens through Telegram, where it offered access to the service for $500/month or a one-time fee of $1,500.

    EvilTokens promotion on Telegram
    EvilTokens promotion on Telegram
    Source: Microsoft

    Add-ons such as anti-bot redirectors, B2B and SMTP sending tools, and an Office 365 capture-link tool were sold separately, and the service provides 44 customizable phishing kits.

    The Lures impersonated document-signing platforms, Microsoft services, cloud identity and file-sharing providers, invoicing systems, voicemail, and eFax services.

    The subject in the phishing emails varies from construction bids, partnership agreements, compensation and benefits notices to requests for proposals, shared files, invoices, and password-expiration warnings.

    The platform's dashboard
    The platform’s dashboard
    Source: Microsoft

    After gaining access to an account, EvilTokens uses Microsoft Graph to map organizational relationships and AI-powered tools to analyze mailbox content and identify high-value targets within the breached environment.

    The platform can search messages for wire-transfer information, pending invoices, and executive correspondence, then generate contextually relevant business email compromise (BEC) messages.

    To evade detection, EvilTokens uses multi-stage redirects, PDFs, HTML attachments, and fake CAPTCHA pages to impede automated analysis, while routing traffic through compromised sites and legitimate cloud platforms such as Vercel, Cloudflare Workers, and AWS Lambda.

    SpyCloud’s dataset shows that EvilTokens was focused on businesses, with roughly 97.5% of compromised accounts belonging to enterprise domains.

    The most targeted countries are the United States, followed by Canada, Australia, the United Kingdom, and Saudi Arabia.

    Victims map
    Victims map
    Source: SpyCloud

    Microsoft and its partners disrupted EvilTokens by obtaining legal authority to seize active infrastructure associated with the phishing service; however, this was not a takedown operation, and the threat remains active, though attacks should noticeably decrease in volume.

    EvilTokens is far from the only device-code phishing platform, and affiliates have already created “clones” such as APToken.

    To defend against these attacks, organizations should disable device-code authentication when it is not required and block the device-code flow wherever possible.

    Users should also verify the application they are authenticating to and avoid proceeding if they are not signing in to an expected app.

    Mitigation and protection guidance also include monitoring for suspicious login activity and using phishing-resistant authentication methods like FIDO2 security keys or passkeys.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    Accounts compromising Disrupted EvilTokens Microsoft PhaaS
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Cyera Raises $400 Million at $12+ Billion Valuation

    Webinar tomorrow: Inside real-world Google Workspace breaches

    New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory

    DORA Year Two: Can Your SOC Actually See the Attack?

    Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal

    The cyber AI parity window now has a deadline

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Trump follows in Hugo Chavez’s footsteps to launch his own TV channel | Media News

    September 22, 2026

    Ed Davey promises tax cuts for millions if UK rejoins EU single market

    September 22, 2026

    Call of Duty’s Activision to make next Halo game as Xbox cuts more jobs

    September 22, 2026

    Cyera Raises $400 Million at $12+ Billion Valuation

    September 22, 2026
    Latest Posts

    COLDCARD security audit phishing attack installs remote access tool

    August 5, 2026

    Reddit aims to make ‘karma’ less important for first-time posters with shift to AI moderation tools

    August 5, 2026

    Right turn on green: is the Telegraph changing its tune on the climate? | Daily Telegraph

    August 5, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Trump follows in Hugo Chavez’s footsteps to launch his own TV channel | Media News

    September 22, 2026

    Ed Davey promises tax cuts for millions if UK rejoins EU single market

    September 22, 2026

    Call of Duty’s Activision to make next Halo game as Xbox cuts more jobs

    September 22, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.