# Microsoft Just Took Down an AI Phishing Service That Hacked 12,000 Inboxes Without a Single Password

By Rafiqul Islam Rabbi · Technology · Published Thu, 24 Sep 2026 14:59:26 GMT
Source: The Current Tribune — https://currenttribune.com/article/microsoft-eviltokens-ai-phishing-takedown

For seven months, a criminal service sold openly on Telegram for as little as $600 let anyone with a grudge and a credit card break into corporate email accounts without ever knowing the victim’s password. This week, Microsoft finally shut it down — but not before it had quietly compromised more than 12,000 inboxes across roughly 10,000 organizations worldwide.

## The Trick: Steal the Login, Skip the Password Entirely

The service, tracked by Microsoft as EvilTokens and run by a threat actor the company labels Storm-2992, didn’t rely on stolen passwords or brute-force attacks. It exploited something far more elegant: the OAuth 2.0 device authorization flow, a legitimate login method originally designed to let devices without keyboards — think smart TVs or conference room hardware — sign into an account by entering a short code shown on screen.

Victims received phishing emails built around 44 different themes — fake invoices, fake RFPs, fake shared-file notifications — all pointing to a link that led to Microsoft’s actual, legitimate login page. The catch was a device code the victim was instructed to enter. Type it in, and the attacker on the other end received a valid access token, no password required, no suspicious login alert triggered, because as far as Microsoft’s systems were concerned, this was just someone authenticating a new device the normal way.

### What Happened After the Break-In

Once inside, attackers didn’t just read email. They created inbox rules to auto-hide incoming security alerts and any replies related to their fraud attempts, granted themselves additional device access to maintain a backdoor even if the original token expired, and quietly exfiltrated sensitive threads — the kind used to set up wire fraud by impersonating a real vendor or executive mid-conversation.

This is where the AI in the platform’s marketing stopped being a buzzword. EvilTokens didn’t just hand criminals raw access — it processed the stolen mailboxes automatically, working across multiple languages to identify which email threads involved active payment discussions and which contacts the victim clearly trusted. It then drafted impersonation messages designed to slot naturally into those existing conversations. Microsoft described the service as one that packaged account takeover, AI-driven mailbox analysis, and fraud tooling into a single commercial service — essentially turning a labor-intensive business email compromise scam into something a low-skill buyer could run at scale.

## The Business Model Behind the Attack

EvilTokens sold three product tiers ranging from $600 to $1,500, plus an ongoing $500 monthly subscription for continued access to updates and infrastructure. It’s a subscription business, in other words, built entirely around defrauding other businesses. Blockchain analysis of the wallets tied to the operation put its total revenue at roughly $1.1 million — a modest sum next to the damage it enabled, since a single successful business email compromise scam can net attackers six figures in a single wire transfer.

The victim geography tells its own story: the highest concentrations of compromised accounts were in the United States, Canada, the United Kingdom, Australia, India, and France — a list that maps closely onto English-language business markets where invoice fraud and vendor impersonation scams tend to be most lucrative.

## How the Takedown Actually Worked

Microsoft didn’t do this alone. The disruption operation pulled in law enforcement along with private-sector partners including Cloudflare, Coinbase, OpenAI, and the credential-monitoring firm SpyCloud. Together they seized 50 websites that made up the service’s storefront and support infrastructure, disabled more than 150 additional supporting domains, and banned hundreds of Cloudflare-hosted domains and Worker projects that were being used to route traffic and evade takedown attempts. UK law enforcement arrested two individuals connected to the operation.

### The Cleanup Is Still Ongoing

SpyCloud, working the recovery side of the operation, says it has managed to recover 8,708 compromised accounts spread across 79 countries — a number that gives some sense of just how far EvilTokens’ reach extended beyond the headline figure of 12,000 inboxes. Recovery in this context means resetting credentials, revoking the fraudulent access tokens, and notifying affected organizations, a process that’s still working through the full victim list.

## What This Means

The device-code phishing technique behind EvilTokens isn’t new — security researchers have warned about OAuth device flow abuse for a couple of years now. What’s new, and what should worry security teams more than the takedown should reassure them, is how easily that technique got packaged into a point-and-click product with AI doing the labor-intensive parts of the scam. Taking down one storefront doesn’t eliminate the underlying vulnerability in how device authorization works, and it doesn’t stop the next group from rebuilding the same service under a different name. If your organization uses device-code sign-in for anything, the actual fix isn’t waiting for the next takedown — it’s training people to never enter a device code they didn’t personally request, full stop.
