Microsoft and UK Police Shut Down EvilTokens Phishing Service
Microsoft's Digital Crimes Unit and UK Metropolitan Police shut down EvilTokens on September 22, a phishing service active since February 2026. It bypassed MFA via OAuth Device Codes, used three LLMs to analyze stolen inboxes and run BEC attacks in 20+ languages, cost $1,500 plus $500/month, and compromised over 12,000 inboxes across 340+ Microsoft 365 organizations.
- Service ran since February 2026, sold via Telegram for $1,500 + $500/month
- 12,000+ inboxes compromised across 340+ Microsoft 365 organizations in 8 countries
- MFA bypassed via OAuth Device Code (RFC 8628); tokens valid for 90 days
- 200 domains seized, two arrests; Microsoft's 40th disruption action
Read next
Security