Microsoft’s Digital Crimes Unit shut down EvilTokens on September 22, 2026, ending a seven-month run that saw the AI-built phishing service compromise more than 12,000 Microsoft 365 inboxes across over 10,000 organizations worldwide. The takedown, backed by a federal court order out of the Eastern District of Virginia, seized 50 websites and disabled more than 150 supporting domains. It marks Microsoft’s 40th court-authorized disruption in nearly two decades of chasing cybercriminal infrastructure, and it is the clearest sign yet that generative AI has moved from a talking point in security conferences to the actual engine room of a criminal business.
EvilTokens did not break Microsoft’s login page or exploit a software bug. It abused a legitimate authentication feature, OAuth’s device authorization flow, and wrapped the whole operation in an AI chatbot that walked criminal customers through each stage of the fraud. Coinbase, Health-ISAC, Cloudflare, OpenAI, SpyCloud, the Shadowserver Foundation and TRM Labs all joined the response, and London’s Metropolitan Police arrested two suspected administrators on September 11, eleven days before Microsoft’s public announcement.
What Happened: Microsoft Dismantles a Turnkey Phishing Business
EvilTokens sold itself as a subscription product, complete with 24/7 support, according to Microsoft’s court filing. Customers paid for access to a dashboard, hosting, phishing templates and an AI assistant that generated lures and coached buyers through each step of a device-code phishing attack. The Microsoft Digital Crimes Unit, or DCU, described the operation in a court brief as one that “operate[d] and sell[s] a turnkey criminal service that steals device-level authentication tokens, converts those tokens into persistent access to victim email accounts, and uses that access to carry out business email compromise (“BEC”) and payment-diversion fraud.”
That description matters because it separates EvilTokens from the credential-stuffing kits and lookalike login pages that dominated phishing-as-a-service for the past decade. EvilTokens never needed a victim’s password. It needed thirty seconds of a distracted employee’s attention and a code copied into the wrong window. Once the DCU secured the court order, Microsoft’s legal and technical teams moved to seize the 50 sites hosting the platform and disable the wider infrastructure supporting it, cutting off the dashboard, the templates and the AI assistant in one coordinated pass.
Inside the Numbers: 12,000 Inboxes, 10,000 Organizations
Microsoft’s own figures put the scale of the damage in stark terms. More than 12,000 customer email inboxes were compromised across more than 10,000 organizations. The United States, Canada, the United Kingdom, Australia, India and France carried the heaviest concentrations of victim activity, though Microsoft did not publish a full country-by-country breakdown. Coinbase separately traced roughly $1.1 million in cryptocurrency payments tied to the operation, a figure that reflects proceeds researchers could follow on-chain rather than a confirmed total of victim losses.
None of the source material reviewed for this story names a sector EvilTokens targeted exclusively. Health-ISAC’s involvement suggests healthcare organizations showed up among the victims, but the ratio of business email compromise attempts across finance, manufacturing, government and other sectors was not disclosed. What is clear: 10,000-plus organizations is a wide net for a service that launched quietly in February 2026 and was first documented publicly by security firm Huntress in March.
| Metric | Figure |
|---|---|
| Compromised inboxes | 12,000+ |
| Organizations affected | 10,000+ worldwide |
| Websites seized | 50 |
| Additional domains disabled | 150+ |
| Cryptocurrency traced (Coinbase) | ~$1.1 million |
| Top-hit countries | US, Canada, UK, Australia, India, France |
| Operational lifespan | February 2026 – September 22, 2026 (~7 months) |
| Arrests | 2 (London, Sept. 11, 2026) |
| Legal mechanism | Federal TRO, US District Court, Eastern District of Virginia |
| DCU disruption count | 40th since the unit’s founding |
How Device-Code Phishing Actually Works
OAuth’s device authorization flow exists for a good reason. It lets a smart TV, a command-line tool, a conferencing box or any device without a browser link to a user’s account by displaying a short code the user types into a real, trusted sign-in page on a second device. No password gets typed on the gadget itself. That is the point, and for years it has been a genuinely useful piece of the OAuth 2.0 standard, documented in RFC 8628 and implemented by Microsoft as part of its Entra identity platform.
The Legitimate Flow, Step by Step
A device requests a device code and a user code from the identity provider. The person is told to visit a genuine Microsoft sign-in page and type in the user code. They authenticate, often completing multi-factor authentication in the process. The identity provider then authorizes the original device to receive an access token. Every step happens on Microsoft’s real infrastructure. Nothing about the process looks suspicious to a trained employee, which is exactly why it became attractive to criminals.
How EvilTokens Weaponized It
In an EvilTokens attack, the criminal’s own system initiates the device-code request and obtains a legitimate code. The victim gets social-engineered, often through an AI-generated message tailored to their role or company, into visiting Microsoft’s real login page and entering that code themselves. The employee sees Microsoft’s actual domain. They may complete MFA exactly as they would on any normal day. But the resulting authorization token gets handed to the attacker’s session, not the victim’s device. From that point, the criminal holds a live, authenticated token for the victim’s mailbox without ever touching a password.
That mechanic explains why conventional defenses miss it. Password managers do not help, because no password gets stolen. Phishing-resistant multi-factor authentication does not fully close the gap either, since the victim genuinely completes MFA, just on the wrong session. Detection has to shift toward monitoring for anomalous device-code grant patterns and enforcing conditional access policies that restrict where and how the device-code flow can be used, a defensive posture covered in more depth in Tech Insider’s Microsoft Defender for Endpoint setup guide.
# Example: hunt for anomalous device-code sign-ins in Microsoft Sentinel / Defender
SigninLogs
| where AuthenticationRequirement == "singleFactorAuthentication"
or ResultType == 0
| where AuthenticationProtocol == "deviceCode"
| summarize count() by UserPrincipalName, AppDisplayName, IPAddress, bin(TimeGenerated, 1h)
| where count_ > 3
AI “at Every Step of the Attack Chain”
Microsoft’s public framing of EvilTokens leaned heavily on the AI angle, and the details back that up. Steven Masada, Associate General Counsel and General Manager at the Microsoft Digital Crimes Unit, said the company had “disrupted EvilTokens, a powerful cybercrime platform that used AI at every step of the attack chain, from compromising email accounts to designing intricate roadmaps for financial fraud and scams,” in a Microsoft blog post announcing the disruption.
According to Microsoft’s disclosures, the platform’s AI chatbot handled reconnaissance on potential victims, wrote phishing lures tuned to a target’s role and organization, and stayed in the conversation with buyers of the service as they ran live attacks, adjusting tactics on the fly. That last piece is what separates EvilTokens from older kits. Previous phishing-as-a-service platforms sold static templates and hoped the buyer knew how to run a con. EvilTokens sold an always-available coach that lowered the skill floor for anyone willing to pay. The court filings and Microsoft’s announcement do not name a specific underlying model or vendor the operators built on, so any claim about a particular large language model powering the kit would go beyond what’s confirmed.
The pattern fits a broader trend Tech Insider has tracked through 2026, including reporting on AI agents reaching sensitive government systems using leaked credentials and the growing need for structured AI red-teaming programs that stress-test models before criminals find the gaps first.
The Coalition Behind the Takedown
Microsoft did not act alone. Coinbase contributed blockchain-tracing work that produced the $1.1 million figure. Health-ISAC, the healthcare-sector information-sharing group, joined the response, consistent with reports of medical organizations among the victims. Cloudflare and Railway helped identify and disable hosting infrastructure. OpenAI’s participation is notable given the AI angle of the case, though the public record does not detail exactly what OpenAI contributed technically. SpyCloud and the Shadowserver Foundation, both regulars in large-scale credential and botnet takedowns, added threat-intelligence support, while TRM Labs handled additional blockchain forensics alongside Coinbase.
The Microsoft Digital Crimes Unit has run this kind of multi-party legal and technical operation since 2008. A Microsoft overview of the DCU’s mission describes the group’s job as leading “Microsoft’s fight against cybercrime to protect our customers and promote global trust in Microsoft.” The EvilTokens case, the unit’s 40th court-authorized disruption, shows how that playbook, originally built for botnets like Citadel and Zeus more than a decade ago, now gets pointed at AI-native criminal services.
Two Arrests in London, Eleven Days Before the Announcement
The UK’s Metropolitan Police arrested two people suspected of administering EvilTokens on September 11, 2026, well before Microsoft went public with the civil takedown on September 22. Neither suspect has been named in the reporting reviewed for this story, and no charges had been detailed publicly as of press time. The gap between arrest and announcement is typical for these cases. Law enforcement needs time to secure evidence and coordinate with private-sector partners before a public disclosure tips off remaining infrastructure operators or customers still holding stolen tokens.
The arrest-then-civil-action sequence echoes recent cybercrime cases Tech Insider has covered, including the Dutch arrest tied to the ShinyHunters investigation, where law enforcement action and corporate disclosure landed on different timelines for similar operational reasons. It’s a reminder that a public takedown announcement is usually the last step in a process that started weeks or months earlier, not the first.
Why This Beats Password-Focused Defenses
Security teams spent the better part of a decade training employees to spot fake login pages and suspicious password prompts. Device-code phishing sidesteps that training entirely. The victim visits a real Microsoft domain. They see real branding. They complete real multi-factor authentication. Nothing in the visual experience signals danger, because nothing about the page is fake. The only thing that’s fake is the context: the code came from an attacker’s session, not the victim’s own device.
That’s why Microsoft’s court filing frames EvilTokens as a token-theft operation rather than a credential-theft one. The brief describes a service built to “converts those tokens into persistent access to victim email accounts,” which is a different threat model from the phishing kits security teams have spent years drilling employees to resist. Organizations that rely purely on user-awareness training and password hygiene have limited ability to stop this style of attack. The more effective controls sit at the identity-platform layer: restricting or disabling the device-code flow where it isn’t needed, enforcing conditional access policies tied to trusted networks and managed devices, and monitoring sign-in logs for the kind of anomalous device-code activity security teams can hunt for using the query pattern shown above.
Historical Context: From 16Shop and LabHost to EvilTokens
Phishing-as-a-service is not new. 16Shop sold payment-card and account-credential phishing kits for years before international law enforcement dismantled it. LabHost, taken down in a coordinated Europol-led operation in 2024, provided hosted phishing pages and a victim-management dashboard to thousands of criminal subscribers, functioning much like a legitimate SaaS company except for the product. Both operations proved the subscription model works for criminals just as well as it works for software vendors: recurring revenue, customer support, and a division of labor between the people who build the tools and the people who use them.
EvilTokens follows that same business logic but swaps static templates for a live AI assistant and swaps fake login pages for abuse of a real authentication standard. That’s a meaningful evolution. Static kits can be fingerprinted, blocklisted and taken down by identifying shared code or hosting patterns. An AI-generated lure changes every time it’s created, and abuse of a legitimate protocol doesn’t trip the same detection signatures as a spoofed login page. Threat-intelligence vendors have separately flagged 2026 as the year AI-generated phishing content started outpacing human-written lures in both volume and believability, a shift the EvilTokens case illustrates in concrete numbers rather than a general trend line.
| Operation | Primary Technique | Scale | Takedown Approach |
|---|---|---|---|
| 16Shop | Static phishing kits for payment-card credentials | Thousands of subscribers globally | International law enforcement, multiple arrests |
| LabHost | Hosted phishing pages, victim-management dashboard | 40,000+ victim data sets (per Europol reporting) | Europol-led coordinated international operation |
| EvilTokens | OAuth device-code abuse plus AI chatbot coaching | 12,000+ inboxes, 10,000+ organizations | Microsoft DCU civil action, federal TRO, 2 UK arrests |
Market Impact: Enterprise Security Budgets Feel the Pressure
For enterprise buyers, EvilTokens adds urgency to a conversation that identity vendors have been pushing for two years: password-focused security spending has diminishing returns against token-theft and consent-phishing techniques. Expect identity providers, including Microsoft, Okta and Ping Identity, to accelerate marketing and product work around conditional access, continuous access evaluation and device-code flow restrictions through the rest of 2026. Cyber-insurance underwriters are also likely to start asking pointed questions about device-code flow exposure during renewal season, the same way they added ransomware-specific questionnaires after 2021’s wave of attacks.
There’s a second-order effect worth watching too. EvilTokens’ business model, subscription pricing with 24/7 support, mirrors legitimate SaaS economics closely enough that some analysts argue phishing-as-a-service has effectively become a shadow software industry with its own competitive dynamics. When Microsoft disrupts one player, it doesn’t eliminate demand, it just opens a gap that a competing kit will try to fill, often within weeks. Organizations that build detection around specific EvilTokens infrastructure rather than the underlying device-code abuse technique risk getting caught flat-footed by the next kit using the same trick under a different name.
Competitive Landscape: The Private-Sector Coalition Model
The roster behind this takedown, Microsoft, Coinbase, Cloudflare, OpenAI, Health-ISAC, SpyCloud, Shadowserver and TRM Labs, illustrates where large-scale cybercrime disruption is heading. No single company or government agency has full visibility into a modern criminal operation that spans identity infrastructure, cryptocurrency payment rails, hosting providers and AI tooling. TRM Labs and Coinbase bring blockchain forensics that traditional cybersecurity vendors don’t have in-house. Cloudflare and Railway bring hosting-infrastructure visibility. OpenAI’s involvement, even without full technical detail disclosed, signals that AI companies are getting pulled into cybercrime response work as their own platforms and techniques show up on both sides of these cases.
This coalition approach increasingly substitutes for, rather than complements, traditional law-enforcement-led takedowns in cases where the infrastructure crosses jurisdictions faster than international legal cooperation can move. Microsoft’s use of a US federal court order to authorize seizure of infrastructure, rather than waiting on a multi-country law enforcement operation, has become the DCU’s standard playbook precisely because it’s faster. The tradeoff is that a private company, not a court with full criminal jurisdiction, ends up making real-time decisions about what infrastructure gets seized and when.
What the Data Tells Security Teams to Do Now
Three concrete actions stand out from the EvilTokens case for any organization running Microsoft 365 or a comparable identity platform. First, audit whether the device-code authentication flow is actually needed across the environment, and disable it for accounts and applications that don’t require it. Second, build or buy detection rules that flag unusual device-code grant patterns rather than relying solely on anomalous-login alerts tuned for password-based attacks. Third, extend security awareness training beyond “check the URL” advice, since device-code phishing defeats that check entirely, toward “verify you initiated the authentication request yourself” as the core habit to teach employees. Combined with the kind of continuous credential exposure checks covered in Tech Insider’s dark web monitoring setup guide, these steps close most of the practical gap EvilTokens exploited.
Five Predictions for the Rest of 2026
- Expect at least one copycat device-code phishing kit to surface within 60 to 90 days, likely marketed on the same criminal forums that hosted EvilTokens customers, since the underlying OAuth abuse technique remains viable industry-wide.
- Microsoft will likely push default restrictions or additional friction on the device-code authorization flow within Entra ID before year-end, given the DCU’s own court filing effectively documents the abuse pattern in detail.
- Other identity providers, not just Microsoft, will publish their own device-code abuse advisories in Q4 2026, since the technique isn’t Microsoft-specific even though this case centered on Microsoft 365 accounts.
- Cyber-insurance carriers will begin adding device-code and token-theft exposure questions to renewal underwriting, mirroring how ransomware-specific questionnaires appeared industry-wide after 2021.
- Expect continued cross-industry coalitions modeled on the EvilTokens response, with AI companies like OpenAI appearing more frequently in cybercrime disruption credits as generative tools show up more often on the attacker side.
The Bigger Picture: AI Cuts Both Ways in Cybercrime
EvilTokens sits at an uncomfortable intersection. The same generative AI capabilities that let defenders automate detection and triage also let criminals automate reconnaissance, lure-writing and real-time coaching for buyers who’d otherwise lack the skill to run a convincing attack. Microsoft’s own framing, that the platform used AI “at every step of the attack chain,” could apply just as easily to a legitimate customer-support product. The technology doesn’t distinguish between helping a support agent answer a ticket and helping a criminal run a business email compromise scheme.
That symmetry is likely to define cybersecurity news through the rest of 2026 and into 2027. Every AI capability that lowers the skill floor for legitimate work lowers it for criminal work too, and the EvilTokens case, with a real dollar figure, a real inbox count and a real court filing behind it, is one of the clearest documented examples yet of that dynamic playing out at scale rather than in the abstract. It joins a growing list of AI-era threats Tech Insider tracks on its cybersecurity threats hub, alongside cases like the ongoing ShinyHunters investigations that show financially motivated crews adapting just as fast as the defenders chasing them.
Frequently Asked Questions
What is EvilTokens?
EvilTokens was a phishing-as-a-service platform that sold device-code phishing kits with an AI chatbot assistant, allowing customers to steal authentication tokens from Microsoft 365 accounts without needing the victim’s password. Microsoft’s Digital Crimes Unit disrupted it on September 22, 2026.
How many people or organizations were affected by EvilTokens?
Microsoft reported more than 12,000 compromised email inboxes across more than 10,000 organizations worldwide, with the heaviest concentrations in the US, Canada, UK, Australia, India and France.
What is device-code phishing?
It’s an attack that abuses OAuth’s legitimate device authorization flow, normally used to log in devices without browsers, such as smart TVs. Attackers trick victims into entering an attacker-generated code on a real Microsoft sign-in page, handing the attacker an authenticated session without ever stealing a password.
Does multi-factor authentication stop device-code phishing?
Not on its own. Victims typically complete real MFA during the attack, since the sign-in page is genuine. The token that results simply goes to the attacker’s session rather than the victim’s own device, which is why identity-platform controls like conditional access matter more than MFA alone here.
Who was behind the EvilTokens takedown?
Microsoft’s Digital Crimes Unit led the legal action under a federal court order from the Eastern District of Virginia. Coinbase, Health-ISAC, Cloudflare, OpenAI, Railway, SpyCloud, the Shadowserver Foundation and TRM Labs all contributed to the response, and London’s Metropolitan Police arrested two suspected administrators.
Were the people behind EvilTokens arrested?
UK police arrested two suspected administrators in London on September 11, 2026, ahead of Microsoft’s public takedown announcement on September 22. Their identities and any charges were not detailed in the public reporting reviewed for this story.
How is EvilTokens different from older phishing-as-a-service platforms like LabHost or 16Shop?
Older kits relied on static, spoofed login pages and templates. EvilTokens abused a legitimate authentication standard instead of faking one, and it wrapped the operation in an AI chatbot that generated lures and coached buyers in real time, lowering the skill needed to run a convincing attack.
What should organizations do to protect against device-code phishing?
Restrict or disable the device-code authentication flow for accounts that don’t need it, deploy conditional access policies tied to trusted networks and managed devices, monitor sign-in logs for anomalous device-code grant patterns, and train employees to verify they personally initiated any authentication request before entering a code.
Related Coverage
- FBI Declares 'Cyber Incident,' 5,000 Agents Notified [2026]
- SharePoint CVE-2026-65660 Hits CISA Deadline [2026]
- Steam Workshop Malware Hits People Playground Twice [2026]
- Kiteworks Tells Users to Shut Down Servers Over Cyberattack Fears [2026]
- Intel TDX vs AMD SEV-SNP vs AWS Nitro: 10% Cost Gap [2026]