Microsoft Takedown of EvilTokens AI‑Powered Device‑Code Phishing Service Disrupts 12,000 Compromised Inboxes
What Happened — Microsoft, with a court order and partners including Health‑ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud and The Shadowserver, dismantled the EvilTokens service. The service leveraged artificial‑intelligence at every stage of a device‑code phishing flow and was linked to roughly 12 000 compromised Microsoft 365 inboxes.
Why It Matters for Trust & Control Assurance
- Demonstrates the risk of credential‑theft attacks that bypass traditional password controls, highlighting the need for continuous monitoring of authentication flows.
- Shows that AI‑enhanced phishing can scale quickly, stressing the importance of a documented security‑awareness program that can be audited and evidenced.
- Aligns with the control objective of “Identity and Access Management – enforce strong authentication, detect anomalous token usage, and train users to recognize phishing.”
Who Is Affected — Enterprises that rely on Microsoft 365 or any Azure AD device‑code flow, spanning technology, finance, healthcare and other sectors.
Recommended Actions
- Enforce MFA for all device‑code and OAuth flows and enable conditional access policies that flag atypical token requests.
- Deploy or refresh a security‑awareness training program that includes AI‑driven phishing simulations.
- Integrate logging of device‑code token exchanges into a SIEM and establish alerts for abnormal patterns. Source: https://thehackernews.com/2026/09/microsoft-takes-down-eviltokens-device.html
Technical Notes
- Attack vector: AI‑assisted phishing using the Azure AD device‑code grant, tricking users into authorizing malicious apps.
- No public CVE; the service exploited legitimate authentication APIs.
- Compromised data: email content, contacts, and potentially internal documents accessed via the hijacked accounts. Source: https://thehackernews.com/2026/09/microsoft-takes-down-eviltokens-device.html