The subscription cost $500 a month and was linked to 12,000 compromised Microsoft 365 mailboxes across more than 10,000 organizations.

 

What happened

Microsoft disrupted EvilTokens, a phishing service operating since February 2026 that had been linked to more than 12,000 compromised Microsoft 365 mailboxes across upwards of 10,000 organizations, CSO Online reported on September 22, 2026. Subscribers paid $1,500 to sign up and $500 a month afterwards, with the service marketed through Telegram channels. Healthcare was among the sectors affected, alongside wholesale distribution, construction, financial services, real estate, and higher education. The platform stole session tokens, the credentials a browser holds after a successful login, rather than passwords, which let its customers hold access to accounts without ever learning the password.

 

Going deeper

What distinguished EvilTokens from earlier services was an AI chatbot that went to work once an account was taken over. The chatbot read the compromised mailbox and produced fraud opportunities from what it found there. Jason Rivera, global field chief information security officer at SimSpace, described the sequence to CSO Online: the software identifies who controls payments, which business relationships carry trust, and which invoices or transactions present openings. It then recommends whom to impersonate and helps write the fraudulent messages, drawing on the genuine conversations already in the mailbox. Automated reconnaissance maps the organization's permissions while token refreshing and inbox monitoring keep the access alive and surface further opportunities.

 

What was said

EvilTokens "combined account compromise, mailbox analysis, target selection, and fraud preparation in a single service," Microsoft wrote in its account of the takedown. The company added that capabilities which previously required experience across identity attacks, cloud systems, social engineering, and financial fraud were available through a ready-made interface. Coinbase traced roughly $1.1 million in revenue to more than 700 cryptocurrency addresses connected to the operation.

 

In the know

Microsoft obtained a US federal court order to seize 50 websites and more than 150 associated domains, working with industry and law enforcement partners, according to CSO Online. UK police arrested two men aged 32 and 38 suspected of running the technology and infrastructure, both were released on bail while seized devices underwent forensic examination. Omair Manzoor, founder and chief executive of ioSENTRIX, attributed the success of the operation to mistakes by the operators, saying the takedown worked because they had used centralizable domains and traceable cryptocurrency payments. He expects more capable versions of the same model to follow.

 

The big picture

Speed is what changes for defenders when the reconnaissance is automated. Manzoor's advice to organizations is to assume every compromised mailbox will be read and exploited by AI within minutes rather than days, and to treat conditional access policies restricting device code sign-in, short token lifetimes, and alerting on unusual authentication as baseline rather than best practice. Healthcare organizations carry the exposure the chatbot was built to find, since revenue cycle teams correspond continuously with payers, billing vendors, and equipment suppliers, and those threads contain the payment authority and trusted relationships the software looks for. Paubox's report on the top three healthcare email attacks identified executive and vendor impersonation as one of three patterns behind nearly every email-related healthcare breach in 2025. An attacker who has read a year of billing correspondence before writing anything does not need to guess at the relationship.

 

FAQs

What is device code sign-in and why do attackers target it?

A Microsoft feature that lets someone sign in on a device without a keyboard, such as a conference room display, by entering a short code on another device. Attackers generate the code themselves and persuade a target to enter it on Microsoft's real login page, which produces a valid session for the attacker without any password changing hands.

 

Why does stealing a session token defeat multifactor authentication?

The token is issued after authentication has already succeeded, including any multifactor step. Anyone holding it resumes that session without being challenged again, which is why revoking sessions matters as much as resetting passwords after a compromise.

 

Can conditional access block device code sign-in entirely?

Yes, through a policy in Microsoft Entra that blocks the authentication flow for all users, with exceptions scoped to the small number of devices that genuinely require it. Auditing current use before applying the block identifies those exceptions.

 

What does anomalous authentication alerting look for?

Sign-ins that do not match an account's established pattern, including unfamiliar client applications, mismatches between the reported application and the connection's characteristics, and a single session appearing from more than one network provider.

 

How would an organization know a mailbox had been read rather than just accessed?

Mailbox auditing records item access and export where the licensing tier and configuration support it. Organizations that have not enabled and retained those logs generally cannot distinguish between an intruder who opened one message and one who read everything.