More than 12,000 email inboxes across over 10,000 organizations were compromised through a large-scale Microsoft 365 attack linked to the EvilTokens cybercrime service.
Microsoft researchers traced the campaign to a phishing-as-a-service platform that abused legitimate device-code authentication to gain access to business accounts. Victims ranged from financial services and healthcare to higher education and other industries worldwide.
A compromised account could also give attackers a trusted foothold for targeting other people inside and outside the organization.
Legitimate Microsoft sign-ins gave attackers account access
EvilTokens relied on a device-code authentication flow originally designed for devices such as smart TVs and conferencing systems. Attackers inserted themselves into that process and supplied victims with a code tied to an attacker-controlled session.
Victims who followed the lure were eventually sent to Microsoft’s real device login page. Entering the supplied code and completing normal authentication could authorize the attacker’s session without exposing the victim’s password to the attacker. MFA could still appear during the process, giving victims another reason to believe the sign-in was legitimate.
Microsoft found that attackers sometimes registered new devices within about 10 minutes of compromise. Other operators waited before creating malicious inbox rules or extracting email data, potentially reducing the chance of immediate detection.
Device-code abuse is not unique to EvilTokens. Researchers have documented other attacks using legitimate Microsoft authentication flows to gain access to business accounts through trusted sign-in infrastructure.
Stolen inboxes became a route to financial fraud
AI tools built into EvilTokens could search compromised mailboxes for financially sensitive people and conversations. The service could identify executives, finance staff, administrators, pending invoices, wire-transfer discussions, and trusted business contacts.
Microsoft Graph access could also help operators map organizational roles and permissions.
Mailbox content could then be summarized and used to support impersonation or business email compromise. Access to genuine accounts gave operators material for messages tied to real payments, projects, or working relationships.
Microsoft and its partners have since disrupted the operation, seizing 50 websites and disabling more than 150 related domains. UK police also arrested two men in connection with the alleged operation.
One compromised inbox can expose people who were never phished
If your organization is investigating a compromised account, do not treat the original mailbox as the only point of exposure. Anyone who exchanged sensitive financial or business information with that employee may also become useful to the attacker.
Teams and employees who regularly work with outside vendors can become follow-on targets once attackers gain access to real business conversations. A message sent from a real account may reference an actual invoice, active project, or familiar contact, allowing malicious activity to blend into normal account use.
Security teams and affected employees should focus on the following checks once compromise is suspected.
- Restrict device-code authentication where it is not needed. Microsoft recommends blocking the flow wherever possible and tightly limiting exceptions to accounts and devices that depend on it.
- Investigate and remove access left behind after compromise. Check newly registered devices, suspicious inbox rules, active sessions, refresh tokens, unusual Microsoft Graph activity, and unexpected outbound messages. Resetting a password alone may not terminate every session.
- Verify unusual financial requests through another channel. Payment changes, wire transfers, invoice updates, and requests involving sensitive information should be confirmed through a known phone number or another trusted method.
Anyone dealing with a compromised Microsoft 365 account should assume attackers may already have learned enough about the organization to approach someone else convincingly. Containment needs to cover both the breached account and the people or business relationships exposed through it.
More cybersecurity news: CVE-2026-93616 let unauthenticated attackers target Check Point Security Management servers with no user interaction required.





