Microsoft seizes 50 domains, arrests two in EvilTokens AI phishing takedown covering 12k accounts
EvilTokens leveraged AI for phishing customization and post-access analysis while abusing device code authentication to steal M365 tokens. Microsoft's seizure of 200 domains and UK arrests of two operators disrupted a service that hit 12,000 accounts. The case highlights rapid commercialization of AI tooling in credential attacks and exposes gaps in legacy auth flows.
Microsoft executed the takedown after tracking EvilTokens since its February 2026 emergence. The platform charged $1,500 initial plus $500 monthly for access to AI-generated lures, inbox scanning, and device code flows that bypass password prompts on M365 tenants. Fifty sites and 150 linked domains were neutralized in coordination with Cloudflare, OpenAI, and Shadowserver.
Technical telemetry shows device code abuse converted user interaction into OAuth tokens without credential theft, enabling persistent mailbox access. AI handled lure personalization across 44 themes and post-compromise prioritization of high-value targets for financial extraction. Arrests followed complaints naming two UK nationals and five unnamed operators.
This operation fits an established pattern of Microsoft-led disruptions against M365-focused services, yet the explicit AI integration at every stage marks a shift from prior commodity kits. Multiple vendors' involvement suggests shared infrastructure mapping rather than isolated action. Device code flows remain exposed because they were designed for constrained hardware without corresponding monitoring hooks.
Expect renewed pressure on OAuth consent and device code logging within enterprise tenants. Similar AI-augmented platforms will likely surface within six months as operators adapt pricing and hosting.
Microsoft: Device code phishing incidents against M365 tenants will fall below 2025 baseline by March 2027 after logging mandates.
Sources (2)
- [1]Primary Source(https://www.securityweek.com/ai-powered-phishing-platform-eviltokens-disrupted-by-microsoft/)
- [2]Supporting Source(https://www.microsoft.com/security/blog/evil-tokens/)