A court-backed disruption, not a final verdict
Microsoft says it has disrupted EvilTokens, a subscription phishing service that combined stolen cloud access with AI-assisted analysis of victims' email. Microsoft and the Health Information Sharing and Analysis Center filed a civil case in the US District Court for the Eastern District of Virginia. A temporary restraining order allowed infrastructure connected to the service to be isolated or redirected while the case proceeds.
Microsoft says the operation took control of 50 websites used to run the service and disabled more than 150 additional domains. Its public court page identifies two named defendants and five unnamed defendants. These are civil allegations, not findings of liability. Microsoft also says UK police arrested two men on suspicion of related offences on September 11. Both were released on police bail; no public outcome has been established.
The login page could still be real
The attack did not need to steal a password on a fake Microsoft page. EvilTokens abused device-code authentication, a legitimate flow designed for devices with limited input, such as conference-room equipment. An attacker generated a sign-in code and persuaded a target to enter it on Microsoft's real device-login page. When the target completed the normal sign-in and any multifactor prompt, the attacker-controlled session received valid access.
That distinction matters. A familiar domain and a successful multifactor check do not prove that the session being approved belongs to the person at the keyboard. Microsoft says stolen tokens could remain useful after a password reset if sessions and refresh tokens were not revoked. In some incidents, attackers registered another device, created inbox rules or copied mail after gaining access.
AI entered after the account was open
EvilTokens then compressed work that once required patient reading. According to Microsoft's investigation, its tools could summarize and translate messages, map organizational roles, find invoice and wire-transfer discussions, and identify people with payment authority. Preset prompts helped a customer choose whom to impersonate and which trusted relationship might support a convincing request.
Microsoft says the service launched in February 2026 and was linked to more than 12,000 compromised inboxes across over 10,000 organizations. It advertised a $1,500 entry fee and a $500 recurring subscription. Those figures come from Microsoft telemetry and investigative material. They describe observed activity, not a complete independent census of every customer, victim or financial loss.
What changes for defenders
The practical lesson is narrower than 'AI makes phishing better.' Once a mailbox is open, automated analysis can expose an organization's informal approval paths quickly. Payment changes, unusual transfers and requests for sensitive data therefore need confirmation through a second trusted channel, even when the message fits an existing conversation.
Microsoft recommends blocking device-code flow where it is not needed, limiting exceptions to specific device accounts, using phishing-resistant authentication and watching for unusual token exchange, device registration and inbox rules. If an account may be compromised, a password change alone is not enough. Active sessions and refresh tokens need attention too. Disrupting one service removes infrastructure; it does not remove the underlying technique.
Sources
- Microsoft Digital Crimes Unit: Disrupting EvilTokensPrimary September 22 account of the civil action, disruption scope, alleged service operation, observed scale and UK arrests.
- Microsoft Threat Intelligence: Unmasking EvilTokensPrimary technical analysis of device-code abuse, token persistence, AI mailbox analysis, indicators and mitigation guidance.
- Microsoft and Health-ISAC v. EvilTokens defendants: public pleadingsPublic court notice for Civil Action 1:26-cv-3047, including the complaint, summonses and temporary-restraint filings.



