HomeIntelligenceBrief
BREACH BRIEF 🟠 High ThreatIntel

Microsoft Takedown of EvilTokens AI‑Powered Device‑Code Phishing Service Disrupts 12,000 Compromised Inboxes

Microsoft, with law‑enforcement and industry partners, dismantled the EvilTokens service that used AI to automate device‑code phishing, leading to 12 000 compromised Microsoft 365 inboxes. The incident underscores the need for robust identity controls and documented security‑awareness programs for audit readiness.

Verisq™ Intelligence · 📅 September 22, 2026 · 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
thehackernews.com

Microsoft Takedown of EvilTokens AI‑Powered Device‑Code Phishing Service Disrupts 12,000 Compromised Inboxes

What Happened — Microsoft, with a court order and partners including Health‑ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud and The Shadowserver, dismantled the EvilTokens service. The service leveraged artificial‑intelligence at every stage of a device‑code phishing flow and was linked to roughly 12 000 compromised Microsoft 365 inboxes.

Why It Matters for Trust & Control Assurance

  • Demonstrates the risk of credential‑theft attacks that bypass traditional password controls, highlighting the need for continuous monitoring of authentication flows.
  • Shows that AI‑enhanced phishing can scale quickly, stressing the importance of a documented security‑awareness program that can be audited and evidenced.
  • Aligns with the control objective of “Identity and Access Management – enforce strong authentication, detect anomalous token usage, and train users to recognize phishing.”

Who Is Affected — Enterprises that rely on Microsoft 365 or any Azure AD device‑code flow, spanning technology, finance, healthcare and other sectors.

Recommended Actions

  • Enforce MFA for all device‑code and OAuth flows and enable conditional access policies that flag atypical token requests.
  • Deploy or refresh a security‑awareness training program that includes AI‑driven phishing simulations.
  • Integrate logging of device‑code token exchanges into a SIEM and establish alerts for abnormal patterns. Source: https://thehackernews.com/2026/09/microsoft-takes-down-eviltokens-device.html

Technical Notes

  • Attack vector: AI‑assisted phishing using the Azure AD device‑code grant, tricking users into authorizing malicious apps.
  • No public CVE; the service exploited legitimate authentication APIs.
  • Compromised data: email content, contacts, and potentially internal documents accessed via the hijacked accounts. Source: https://thehackernews.com/2026/09/microsoft-takes-down-eviltokens-device.html
📰 Original Source
https://thehackernews.com/2026/09/microsoft-takes-down-eviltokens-device.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →