Microsoft 365 Attack Compromises 12,000 Inboxes Across 10,000 Organizations

Written By
Liz Ticong
Liz Ticong
Sep 25, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

More than 12,000 email inboxes across over 10,000 organizations were compromised through a large-scale Microsoft 365 attack linked to the EvilTokens cybercrime service.

Microsoft researchers traced the campaign to a phishing-as-a-service platform that abused legitimate device-code authentication to gain access to business accounts. Victims ranged from financial services and healthcare to higher education and other industries worldwide.

A compromised account could also give attackers a trusted foothold for targeting other people inside and outside the organization.

Legitimate Microsoft sign-ins gave attackers account access

EvilTokens relied on a device-code authentication flow originally designed for devices such as smart TVs and conferencing systems. Attackers inserted themselves into that process and supplied victims with a code tied to an attacker-controlled session.

Victims who followed the lure were eventually sent to Microsoft’s real device login page. Entering the supplied code and completing normal authentication could authorize the attacker’s session without exposing the victim’s password to the attacker. MFA could still appear during the process, giving victims another reason to believe the sign-in was legitimate.

Microsoft found that attackers sometimes registered new devices within about 10 minutes of compromise. Other operators waited before creating malicious inbox rules or extracting email data, potentially reducing the chance of immediate detection.

Device-code abuse is not unique to EvilTokens. Researchers have documented other attacks using legitimate Microsoft authentication flows to gain access to business accounts through trusted sign-in infrastructure.

Stolen inboxes became a route to financial fraud

AI tools built into EvilTokens could search compromised mailboxes for financially sensitive people and conversations. The service could identify executives, finance staff, administrators, pending invoices, wire-transfer discussions, and trusted business contacts.

Microsoft Graph access could also help operators map organizational roles and permissions.

Mailbox content could then be summarized and used to support impersonation or business email compromise. Access to genuine accounts gave operators material for messages tied to real payments, projects, or working relationships.

Microsoft and its partners have since disrupted the operation, seizing 50 websites and disabling more than 150 related domains. UK police also arrested two men in connection with the alleged operation. 

Advertisement

One compromised inbox can expose people who were never phished

If your organization is investigating a compromised account, do not treat the original mailbox as the only point of exposure. Anyone who exchanged sensitive financial or business information with that employee may also become useful to the attacker.

Teams and employees who regularly work with outside vendors can become follow-on targets once attackers gain access to real business conversations. A message sent from a real account may reference an actual invoice, active project, or familiar contact, allowing malicious activity to blend into normal account use.

Security teams and affected employees should focus on the following checks once compromise is suspected.

  • Restrict device-code authentication where it is not needed. Microsoft recommends blocking the flow wherever possible and tightly limiting exceptions to accounts and devices that depend on it.
  • Investigate and remove access left behind after compromise. Check newly registered devices, suspicious inbox rules, active sessions, refresh tokens, unusual Microsoft Graph activity, and unexpected outbound messages. Resetting a password alone may not terminate every session.
  • Verify unusual financial requests through another channel. Payment changes, wire transfers, invoice updates, and requests involving sensitive information should be confirmed through a known phone number or another trusted method.

Anyone dealing with a compromised Microsoft 365 account should assume attackers may already have learned enough about the organization to approach someone else convincingly. Containment needs to cover both the breached account and the people or business relationships exposed through it.

More cybersecurity news: CVE-2026-93616 let unauthenticated attackers target Check Point Security Management servers with no user interaction required.

Liz Ticong

Liz Ticong is a staff writer for eWeek and TechRepublic focused on AI, cybersecurity, enterprise software, and data. She has more than 10 years of editorial experience as a technology industry writer, combining reporting, product research, and hands-on software testing in her coverage. Her work has been published on Datamation, Enterprise Networking Planet, and TechnologyAdvice.com. She writes technology news, software reviews, product comparisons, and buyer’s guides for business and IT readers.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.