Microsoft said this week it has disrupted EvilTokens, a phishing-as-a-service platform that compromised more than 12,000 email inboxes across upwards of 10,000 organizations worldwide by abusing a legitimate Microsoft sign-in feature and automating much of the attack with an integrated AI chatbot.

The takedown combined a civil legal action authorized by the U.S. District Court for the Eastern District of Virginia with a criminal operation by London's Metropolitan Police Service, which arrested two people, ages 32 and 38, on September 11. Microsoft said it seized 50 websites tied to the service and disabled more than 150 supporting infrastructure domains, while Cloudflare separately banned hundreds of domains and suspended accounts linked to the operation.

How the scheme worked

EvilTokens exploited OAuth 2.0's device authorization flow, a legitimate feature built to let sign-in-limited devices like smart TVs or printers authenticate through a browser on another device. Victims received phishing messages containing a device code and were directed to enter it at Microsoft's own device login page. Because the victim was authenticating through Microsoft's real sign-in page, the flow granted attackers a valid access token, letting them into the account without ever needing, or triggering, a password prompt.

To slip past spam filters and security scanners, the service routed its phishing infrastructure through legitimate cloud platforms including Cloudflare Workers and AWS Lambda, adding layers of legitimate-looking hosting between the victim and the attacker's actual infrastructure.

Independent researchers at SpyCloud, tracking the same campaign, identified 8,708 unique victim accounts spanning 6,585 corporate domains across 79 countries, with the heaviest concentration of victims in the United States, Canada, the United Kingdom, Australia, India and France. Targeted sectors skewed toward wholesale distribution, construction, financial services, real estate, higher education and healthcare, industries where a compromised inbox can be used to intercept and redirect real invoice payments.

An AI chatbot ran the operation

What distinguished EvilTokens from earlier device-code phishing kits, according to Microsoft, was an AI chatbot built into the platform and "integrated at every step of the attack chain." Once an inbox was compromised, the AI system scanned its contents in more than 20 languages to identify active payment conversations and relationships the victim trusted, then recommended fraud strategies and drafted convincing impersonation messages to redirect payments or extract further credentials.

Researchers who examined the toolkit told reporters they found evidence the platform itself had been built with substantial AI coding assistance, lowering the technical bar for whoever operated it. That combination, an AI system doing both the building and the running of a criminal operation, is what security researchers have flagged as the more durable shift: tasks that used to require a skilled human operator working one victim at a time can now run against thousands of inboxes with comparatively little manual effort.

What organizations should do

Because device-code phishing exploits a legitimate authentication flow rather than a software vulnerability, patching alone will not stop it. Security researchers recommend organizations restrict or disable device-code sign-in entirely where it is not operationally necessary, apply conditional access policies that flag authentications from unfamiliar devices or locations, and train staff to treat any unsolicited request to enter a device code as a red flag rather than routine friction.

Microsoft said it will continue pursuing legal action against remaining infrastructure tied to the service and is sharing indicators of compromise with industry partners to help affected organizations identify whether they were touched by the campaign.

Sources