Protect.Computer
NEWS

Microsoft Disrupts EvilTokens Phishing Service, 2 Arrested

· 1 min read · Digital scams Identity theft
Microsoft Disrupts EvilTokens Phishing Service, 2 Arrested

Microsoft’s Digital Crimes Unit has disrupted EvilTokens, a phishing-as-a-service (PhaaS) platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations worldwide. Working with the Health-ISAC, law enforcement, and identity threat firm SpyCloud, Microsoft seized the active infrastructure behind the service — and two suspected administrators were arrested in the UK.

The Metropolitan Police executed warrants at addresses in Canary Wharf and Nine Elms on Friday, detaining men aged 32 and 38. Both were released on bail pending further investigation. EvilTokens emerged in February 2026 and quickly became notable as the first PhaaS operation to offer AI-powered features — including tools that automatically sift through compromised inboxes to identify high-value targets and generate customized phishing lures. The service was sold for $500 per month or a one-time fee of $1,500, with add-on modules including anti-bot redirectors and Office 365 capture tools.

The platform worked by abusing Microsoft’s OAuth 2.0 device-authorization flow, a mechanism designed to let devices with limited input — smart TVs, printers, Teams phones — authenticate without a keyboard. Attackers would trigger a device-code request, send the resulting code to victims via phishing email, and when the victim authenticated on Microsoft’s legitimate login portal, the attacker captured their session token without ever touching their password. This technique bypasses MFA entirely. Targeted sectors included financial services, healthcare, higher education, construction, and real estate. Microsoft tracked the group behind EvilTokens as Storm-2992. The takedown disrupted infrastructure but did not constitute a full shutdown — Microsoft noted attacks will likely decrease but the threat remains active.

Sources

Related reading