Download Privacy Needle App

Type to search

Cybersecurity

Microsoft Disrupts EvilTokens Phishing Platform Following 12,000 Account Compromises

Share

Microsoft’s Digital Crimes Unit (DCU) has disrupted the EvilTokens phishing-as-a-service (PhaaS) platform, which was responsible for compromising more than 12,000 Microsoft accounts across 10,000 organisations.

The disruption involved a coordinated effort between Microsoft, law enforcement, the Health-ISAC, and the identity threat protection company SpyCloud. Following the investigation, the Metropolitan Police Service arrested two men, aged 32 and 38, at addresses in Canary Wharf and Nine Elms in London. Both suspects, believed to be administrators of the EvilTokens website, have been released on bail pending further investigation.

AI-Powered Phishing and Device-Code Abuse

Microsoft tracks the threat actor behind the platform as Storm-2992. The group utilised the EvilTokens platform to execute sophisticated business email compromise (BEC) campaigns, targeting sectors including healthcare, financial services, construction, and higher education.

The service specialised in device-code phishing, a technique that abuses the legitimate OAuth 2.0 device-authorisation flow. This flow is designed for devices with limited input capabilities, such as smart TVs, printers, or conferencing equipment. By initiating a device-code request and sending the code to a target as part of a phishing lure, attackers can obtain authentication tokens that bypass multi-factor authentication (MFA) protections without needing to steal actual user credentials.

EvilTokens also integrated artificial intelligence to enhance its operations. The platform used AI-powered tools to customise phishing lures and sift through compromised inboxes to identify high-value targets. Once access was gained, the service used Microsoft Graph to map organisational relationships and search for sensitive information, such as wire-transfer details, pending invoices, and executive correspondence.

Impact and Residual Risks

Data from SpyCloud indicates that the platform’s impact was widespread, with more than 8,708 compromised accounts identified across 6,585 corporate email domains in 79 countries. Approximately 97.5% of the affected accounts belonged to enterprise domains, with the United States, Canada, Australia, and the United Kingdom among the most targeted nations.

While the operation successfully seized active infrastructure associated with the service, Microsoft noted that the disruption does not constitute a full takedown. The threat remains active, and affiliates have already developed clones of the platform, such as APToken.

To defend against device-code phishing, organisations should disable device-code authentication where it is not strictly required and block the device-code flow wherever possible. Security experts also recommend implementing phishing-resistant authentication methods, such as FIDO2 security keys or passkeys, and monitoring for suspicious login activity.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.