When Phishing Gets an AI Analyst: What the EvilTokens Takedown Means for Your Business

Phishing used to take patience. A criminal had to research a target, guess at the right pretext, and hope a generic "invoice attached" email landed on the right desk. This week, Microsoft pulled back the curtain on an operation that had automated all of that work — and sold it as a subscription service.
On September 22, Microsoft announced it had dismantled EvilTokens, a phishing-as-a-service platform that compromised more than 12,000 email inboxes across over 10,000 organizations worldwide, spanning wholesale distribution, construction, financial services, real estate, higher education, and healthcare. Working with a U.S. federal court order, Microsoft seized 50 websites and disabled more than 150 domains tied to the operation. London's Metropolitan Police arrested two men, aged 32 and 38, on September 11. Partners in the takedown included Cloudflare, Coinbase, OpenAI, SpyCloud, TRM Labs, and the Shadowserver Foundation.
The technique: device-code phishing
EvilTokens didn't steal passwords in the traditional sense. It exploited a legitimate Microsoft sign-in feature called the device authorization flow — the same mechanism that lets you log into a streaming app on your smart TV by entering a short code on your phone. Victims received emails built around 44 different lures (fake invoices, RFPs, shared files) that led to a background script generating a live, real device code. The page then showed a convincing "Continue with Microsoft" button. When the victim entered that code on Microsoft's own, legitimate login portal, the attacker's client received a valid access token and refresh token — no password theft required, and persistence that can survive a password reset if the underlying session stays alive.
Where AI comes in
What made EvilTokens more than "just another phishing kit" was what happened after the break-in. According to Microsoft, the platform ran an AI-powered "analyst" chatbot that read through compromised mailboxes automatically, mapping organizational hierarchies, identifying who approves payments, spotting trusted vendor relationships, and drafting believable impersonation messages grounded in real email threads. Much of the platform itself appears to have been built with AI coding assistance, which lowered the technical bar for the people running it. All of this was packaged with support, dashboards, and tiered pricing — a "B2B sender" add-on for $600, an Office 365 capture link for $1,500 up front plus $500 a month. Investigators traced roughly $1.1 million in platform revenue.
Security researcher Jason Rivera summed up the shift well: capabilities that used to require real expertise in identity attacks, cloud systems, social engineering, and financial fraud were suddenly available through a point-and-click interface. Another practitioner, Omair Manzoor, put the new baseline in stark terms — organizations should now assume a compromised mailbox will be read and exploited by AI within minutes, not days.
Why this matters beyond IT
For finance and operations teams, this isn't an abstract security story — it's a direct threat to the processes that move money. An AI system that can read a real invoice thread, identify the actual approver, and draft a convincing follow-up email is purpose-built for exactly the kind of payment-redirection and vendor-impersonation fraud that finance teams have spent years training people to spot. The old advice — "watch for bad grammar and mismatched sender addresses" — doesn't hold up against messages generated from a company's own correspondence.
The practical defenses haven't changed dramatically, but they've become non-negotiable rather than optional. Restrict or disable device-code sign-in flows through conditional access policies unless there's a specific business need for them. Shorten token and refresh-token lifetimes, and make sure a password reset actually revokes existing sessions rather than just changing a credential. Monitor for new inbox forwarding rules and newly registered devices, both classic signs of a mailbox already in someone else's hands. And keep — or build — a habit of verifying any changed payment details or unusual vendor request through a second channel, ideally a phone call to a known number, not a reply to the email itself.
EvilTokens is gone, but the model it proved out — AI doing the reconnaissance and drafting work that used to require a skilled human — isn't going anywhere. Expect variations on this theme, and treat identity and access hygiene as the frontline defense, because by the time a phishing email looks personal, it's because something on your side has already been read.
Sources: The Hacker News (thehackernews.com/2026/09/microsoft-takes-down-eviltokens-device.html), CSO Online (csoonline.com/article/4225175), BleepingComputer (bleepingcomputer.com/news/security/eviltokens-phaas-disrupted-after-compromising-12-000-microsoft-accounts), Help Net Security (helpnetsecurity.com/2026/09/23/microsoft-eviltokens-phishing-service-disrupted), Axios (axios.com/2026/09/22/microsoft-eviltokens-court-takedown)

Comments