Microsoft disrupts EvilTokens device-code phishing service
EditorialBy TrustList Editorial
Microsoft has seized EvilTokens’ sites and says the device-code phishing service reached more than 12,000 inboxes. Block device code sign-in in Conditional Access and revoke tokens, not just passwords.
About Microsoft disrupts EvilTokens device-code phishing service
Microsoft disrupts EvilTokens device-code phishing service
22 September 2026 — Microsoft said on 22 September 2026 that its Digital Crimes Unit had seized 50 websites and disabled more than 150 further domains used by EvilTokens, a phishing-as-a-service platform. It acted with authorisation from the US District Court for the Eastern District of Virginia. Microsoft links the service to more than 12,000 compromised inboxes at more than 10,000 organisations worldwide since it appeared in February 2026. It tracks the group behind the service as Storm-2992.
How the attacks worked
EvilTokens abused the OAuth 2.0 device code flow, the sign-in method built for keyboardless devices such as conference-room equipment and smart TVs. The victim is persuaded to enter a code on a genuine Microsoft sign-in page. That hands the attacker a token for the victim's account, and the attacker never needs the password. Microsoft says the service then used an AI chatbot to read compromised mailboxes and pick out trusted contacts, payment approvals and invoices that could be used for fraud.
UK arrests
Microsoft says the Metropolitan Police Service's cybercrime team arrested two men, aged 32 and 38, on 11 September 2026. Both have been released on bail while the investigation continues. The Record (22 September) reported that the men were arrested on suspicion of making articles for use in fraud and of money laundering.
Who is affected
This affects any organisation on Microsoft 365 or Entra ID that still allows ordinary users to sign in with device codes. The takedown removes one group's infrastructure, but other groups can still use the technique.
What buyers should do
Microsoft's threat intelligence post sets out the controls. The main ones are these:
- Block the device code flow with a Conditional Access policy wherever possible. Allow exceptions only for named accounts that need it, such as Teams meeting-room devices.
- Use phishing-resistant multifactor authentication, such as FIDO2 security keys or passkeys, and block legacy authentication.
- If you suspect an account is compromised, disable it, revoke its refresh tokens and sessions, and review sign-in logs and any new inbox rules. A password reset alone does not cancel a stolen token.
- Treat any request to change bank details or approve an unusual payment as unverified until it is confirmed through a separate, trusted channel. Microsoft advises assuming that criminals can understand a compromised inbox "in minutes, not days".
- Brief finance staff and executive assistants in particular. Device-code lures often look like a routine sign-in request from a colleague.
- Check whether your managed service provider has already applied these policies to your tenant, and ask for evidence.
Sources
- Microsoft On the Issues: Disrupting EvilTokens: The AI Chatbot Built for Cybercrime — 22 September 2026
- Microsoft Security Blog: Unmasking EvilTokens: Getting to the root of device code phishing — 22 September 2026
- The Record: Two arrested in UK after Microsoft takedown of EvilTokens — 22 September 2026
- The Register: UK cops arrest 2 EvilTokens suspects, Microsoft seizes 50 phishing kit websites — 22 September 2026
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.