Microsoft's Digital Crimes Unit says it has disrupted a criminal service called EvilTokens. Since it appeared in February 2026, the service has been linked to more than 12,000 compromised mailboxes across over 10,000 organisations.

Two things set EvilTokens apart from an ordinary phishing kit: it got in without stealing passwords, and once inside it used an AI chatbot to decide what to do next.

Entry without a password: device code phishing

The attack abuses the OAuth 2.0 device code flow. The victim receives a link or attachment showing a device code, then enters that code on Microsoft's real sign-in page. The page is genuine, so the usual phishing tells are absent. The moment the code is entered, the attacker receives access and refresh tokens.

The result is full access to the mailbox without ever learning the password. Worse, as The Hacker News reports, that access can survive a password change: unless sessions and tokens are revoked as well, the attacker stays inside. With the tokens they can register new devices, add inbox rules and exfiltrate mail.

What the chatbot did

At the centre of the service was a chatbot that read the compromised mailbox. According to Microsoft it could:

  • Summarise and translate correspondence in more than 20 languages.
  • Surface wire-transfer conversations and the people who approve payments.
  • Map roles and trusted relationships inside the organisation.
  • Recommend who was most credible to impersonate, and draft messages in that person's voice.

Preset prompts let a criminal do all of this in a click. The difference Microsoft stresses is speed: mailbox reconnaissance that used to take days now takes minutes.

Scale and the operation

The service was sold through a Telegram storefront for a $1,500 initiation fee plus a $500 recurring subscription. Coinbase traced roughly $1.1 million in platform revenue. Victims were concentrated in the United States, Canada, the United Kingdom, Australia, India and France, across wholesale distribution, construction, financial services, real estate, higher education and healthcare.

Microsoft obtained authorisation from the U.S. District Court for the Eastern District of Virginia and, with co-plaintiff Health-ISAC and partners including Cloudflare, Coinbase and OpenAI, seized 50 websites and disabled more than 150 supporting domains. In the UK, the Metropolitan Police cybercrime team arrested two men aged 32 and 38 on 11 September 2026; both were released on bail while the investigation continues.

What organisations should do

Microsoft's advice targets the flow rather than the AI:

  • Restrict the device code flow with conditional access policies unless it is genuinely needed.
  • If you suspect an account is compromised, changing the password is not enough; revoke sessions and tokens too.
  • Verify any request to change payment details, redirect funds or approve an unusual transaction through a second trusted channel.

The last point matters most. What makes this attack persuasive is that the message really does come from a familiar address and is written in the company's own language. What catches it is not a technical filter but a single phone call to confirm.