AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft
EvilTokens was an AI-powered phishing platform that enabled cybercriminals to compromise over 12,000 email accounts across more than 10,000 organizations worldwide by abusing device code authentication flows. The platform used AI to craft targeted phishing messages, select victims, and extract valuable data from compromised accounts. Microsoft disrupted the platform by seizing infrastructure and arresting two suspects linked to its operation. The platform charged users for access and offered numerous phishing themes to increase success rates.
AI Analysis
Technical Summary
EvilTokens was a cybercrime platform leveraging AI throughout the phishing attack chain, including generating social engineering messages, selecting targets, and analyzing compromised inboxes. It exploited device code authentication flows, where users enter short codes from devices into browsers, to gain access tokens without passwords. The platform emerged in February 2026 and was used to compromise over 12,000 email accounts at more than 10,000 organizations globally. Microsoft disrupted EvilTokens by seizing 50 websites and disabling over 150 domains, and arrested two suspects in the UK. The platform operated as a paid service charging $1,500 initial and $500 monthly fees. Multiple cybersecurity organizations collaborated in the takedown.
Potential Impact
The platform enabled attackers to bypass traditional password-based authentication by abusing device code authentication flows, allowing persistent access to targeted email accounts. Over 12,000 accounts at more than 10,000 organizations worldwide were compromised, potentially exposing sensitive communications and data. The AI-driven approach increased the effectiveness of phishing campaigns and post-compromise exploitation, raising the risk of financial fraud and data theft.
Mitigation Recommendations
Microsoft has disrupted the EvilTokens platform by seizing infrastructure and arresting key suspects, effectively mitigating the threat. Organizations should ensure device code authentication flows are monitored and consider additional controls to detect suspicious authentication activities. No direct patch is applicable as this is an attack platform rather than a software vulnerability. Continued vigilance against phishing and suspicious authentication requests remains important.
Affected Countries
United States, Canada, United Kingdom, Australia, India, France
AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft
Description
EvilTokens was an AI-powered phishing platform that enabled cybercriminals to compromise over 12,000 email accounts across more than 10,000 organizations worldwide by abusing device code authentication flows. The platform used AI to craft targeted phishing messages, select victims, and extract valuable data from compromised accounts. Microsoft disrupted the platform by seizing infrastructure and arresting two suspects linked to its operation. The platform charged users for access and offered numerous phishing themes to increase success rates.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
EvilTokens was a cybercrime platform leveraging AI throughout the phishing attack chain, including generating social engineering messages, selecting targets, and analyzing compromised inboxes. It exploited device code authentication flows, where users enter short codes from devices into browsers, to gain access tokens without passwords. The platform emerged in February 2026 and was used to compromise over 12,000 email accounts at more than 10,000 organizations globally. Microsoft disrupted EvilTokens by seizing 50 websites and disabling over 150 domains, and arrested two suspects in the UK. The platform operated as a paid service charging $1,500 initial and $500 monthly fees. Multiple cybersecurity organizations collaborated in the takedown.
Potential Impact
The platform enabled attackers to bypass traditional password-based authentication by abusing device code authentication flows, allowing persistent access to targeted email accounts. Over 12,000 accounts at more than 10,000 organizations worldwide were compromised, potentially exposing sensitive communications and data. The AI-driven approach increased the effectiveness of phishing campaigns and post-compromise exploitation, raising the risk of financial fraud and data theft.
Defensive Guidance
Microsoft has disrupted the EvilTokens platform by seizing infrastructure and arresting key suspects, effectively mitigating the threat. Organizations should ensure device code authentication flows are monitored and consider additional controls to detect suspicious authentication activities. No direct patch is applicable as this is an attack platform rather than a software vulnerability. Continued vigilance against phishing and suspicious authentication requests remains important.
Affected Countries
Technical Details
- Classification
- {"confidence":0.88,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/ai-powered-phishing-platform-eviltokens-disrupted-by-microsoft/","fetched":true,"fetchedAt":"2026-09-23T11:32:46.476Z","wordCount":1107}
Threat ID: 6ab3b8def7a7c54106b23f06
Added to database: 09/23/2026, 11:32:46 UTC
Last enriched: 09/23/2026, 11:32:53 UTC
Last updated: 09/23/2026, 11:32:53 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.