Microsoft, with industry and law enforcement partners, has dismantled EvilTokens, an AI-driven platform that facilitated sophisticated phishing attacks. The service, active since February 2026, compromised over 12,000 Microsoft 365 inboxes across more than 10,000 organizations globally.

The EvilTokens platform offered cybercriminals an end-to-end service for mass account compromise and financial fraud. It utilized artificial intelligence at multiple stages of its attack chain, from crafting personalized phishing lures to analyzing compromised inboxes for lucrative fraud opportunities. This AI integration allowed for unprecedented speed and efficiency in executing business email compromise (BEC) scams and other financial crimes. Microsoft's Digital Crimes Unit led the disruption, seizing infrastructure and disabling numerous websites and domains associated with the operation.

The EvilTokens platform emerged in February 2026 and quickly became a prominent phishing-as-a-service (PhaaS) provider. It specialized in abusing Microsoft's OAuth 2.0 device-code authentication flow, a method that allowed attackers to steal access tokens and gain persistent access to accounts without capturing user credentials or triggering traditional multi-factor authentication (MFA) prompts. This technique effectively bypassed MFA by redirecting victims through legitimate Microsoft authentication processes, resulting in tokens being issued to the attacker's client ID.

At the core of EvilTokens was an AI-powered chatbot that analyzed compromised inboxes. This chatbot could identify trusted relationships, payment authorizations, and other sensitive details, enabling cybercriminals to develop intricate roadmaps for financial fraud. The platform also assisted in drafting impersonation messages, leveraging actual business conversations to create convincing lures. For instance, it could map organizational structures and permissions using Microsoft Graph, facilitating lateral movement within compromised networks. The service was marketed on Telegram with an initial fee of $1,500 and a recurring $500 monthly subscription.

Microsoft attributes the development and support of EvilTokens to a threat actor group known as Storm-2992. As part of the coordinated takedown, Microsoft, alongside industry partners like Health-ISAC and SpyCloud, obtained a U.S. federal court order to seize 50 websites and disable over 150 associated domains. In the United Kingdom, law enforcement arrested two men, aged 32 and 38, suspected of operating the platform's technology and infrastructure.

The disruption of EvilTokens highlights the increasing sophistication of cybercrime, particularly the integration of AI into attack methodologies. While the EvilTokens platform has been taken down, the underlying techniques and the model of AI-enabled cybercrime are expected to persist. Microsoft advises organizations to consider disabling device-code authentication if it is not required for their operations, as this specific attack vector can be fully blocked by disabling this feature in Conditional Access policies.