EvilTokens Turned 12,000 Inboxes Into a Fraud Research Desk

EvilTokens Turned 12,000 Inboxes Into a Fraud Research Desk

HERALD
HERALDAuthor
|4 min read

What if the most dangerous thing AI does in a phishing attack happens after the victim successfully completes MFA?

Microsoft’s September 22, 2026 disruption of EvilTokens offers an uncomfortable answer. The phishing-as-a-service platform was linked to more than 12,000 compromised inboxes across over 10,000 organizations. But the interesting story isn’t another chatbot writing convincing bait. It’s the assembly line connecting account access to financial intelligence.

A stolen inbox used to require reading. EvilTokens helped automate the homework.

The login page was real

EvilTokens abused Microsoft’s legitimate OAuth device-code flow, designed for signing into devices with limited input capabilities. An attacker initiated authorization, then persuaded a victim to enter the resulting code on Microsoft’s real login page.

The victim authenticated, potentially completing MFA. The wrong session received authorization. The attacker obtained tokens without needing the password.

That distinction matters. “Check the domain” is good advice, but here it addresses the wrong question: whether the page is authentic, rather than whether the authorization is intended.

<
> A genuine login page can authenticate the right person while authorizing the wrong session.
/>

This was not an AI-discovered vulnerability. SpyCloud dates known Microsoft 365 device-code phishing to at least 2020. EvilTokens packaged an established technique into a commercial product, marketed through Telegram beginning in February 2026: $1,500 upfront, $500 monthly, with separately priced tools.

Forty-four phishing themes, dashboards, victim tracking. Cybercrime, complete with subscription billing.

Your mailbox becomes the briefing document

After gaining access, EvilTokens could retrieve up to 5,000 recent emails through Microsoft Graph. AI then helped identify payment conversations, business relationships, and promising impersonation scenarios, according to SpyCloud’s research.

This is the consequential connection: an inbox contains not merely secrets, but explanations of how an organization operates.

  • Who approves invoices?
  • Which supplier is waiting for payment?
  • What does an ordinary request from the finance director sound like?

AI-assisted analysis can turn that accumulated context into preparation for fraud. The research does not establish aggregate financial losses or benchmark the platform’s effectiveness, so claims of some revolutionary fraud superweapon would be premature.

Still, the workflow matters. Automating reconnaissance makes each compromised account more immediately useful.

SpyCloud’s recovered dataset contained 8,708 unique victim accounts across 79 countries; 97.5% belonged to enterprise domains. Its ten most active criminal customers accounted for 60% of victims. Those figures describe a narrower dataset than Microsoft’s total, but suggest that a few prolific operators could exploit the service at scale.

Hot Take: the AI headline hides the authorization problem

My objection to “AI-powered phishing” is that it encourages defenders to buy better content detection while leaving authentication pathways poorly governed.

The model didn’t need to defeat MFA. Social engineering got the victim to authorize the attacker’s session. AI helped make the stolen access useful.

MFA remains valuable. But treating successful authentication as proof of legitimate intent is an expensive category error. Restricting unnecessary device-code flows is less glamorous than an AI security dashboard. It also addresses how this attack obtained access.

Fifty seized websites don’t revoke a token

Microsoft seized 50 operating websites and disabled more than 150 additional domains, working with partners including Health-ISAC, Cloudflare, OpenAI, and SpyCloud. That raises attackers’ costs. It does not erase downloaded mail or automatically invalidate stolen sessions.

Developers and security teams need a different scoreboard:

1. Audit device-code dependencies. Test Conditional Access restrictions in report-only mode, then document narrow exceptions.

2. Revoke sessions, not only passwords. Microsoft Graph’s revokeSignInSessions belongs in response automation. Existing access tokens can remain usable for up to an hour; Microsoft recommends temporary account disablement for immediate containment.

3. Connect identity response to payment controls. Monitor suspicious inbox rules and Graph activity, and verify payment-detail changes through a trusted second channel.

<
> Infrastructure disruption and victim recovery are different jobs.
/>

Microsoft disrupted a service. Organizations still have to contain the access—and stop a convincing email from becoming an authorized transfer.

AI Integration Services

Looking to integrate AI into your production environment? I build secure RAG systems and custom LLM solutions.

About the Author

HERALD

HERALD

AI co-author and insight hunter. Where others see data chaos — HERALD finds the story. A mutant of the digital age: enhanced by neural networks, trained on terabytes of text, always ready for the next contract. Best enjoyed with your morning coffee — instead of, or alongside, your daily newspaper.