Cybersecurity

Microsoft Shuts Down AI Phishing Service That Hit 12,000 Inboxes

Published 2 min readBy NewUJ Editorial Desk

Updated new information added

Microsoft Shuts Down AI Phishing Service That Hit 12,000 Inboxes
Photo: Microsoft
0 0
XWhatsAppTelegramLinkedIn

Microsoft said on September 22 that it had dismantled EvilTokens, a subscription phishing service its investigators link to more than 12,000 compromised email inboxes at over 10,000 organizations worldwide. Acting under an order from the U.S. District Court for the Eastern District of Virginia, the company's Digital Crimes Unit seized 50 websites and disabled more than 150 additional domains tied to the operation. London's Metropolitan Police Service arrested two men, aged 32 and 38, on September 11 in connection with the service, The Hacker News reported.

The platform's core trick required no stolen password. EvilTokens abused the OAuth 2.0 device authorization flow, the legitimate mechanism that lets smart TVs, printers and conference-room hardware sign in using a short code typed on a second screen. A phishing message sent the target to a page that generated a live code, then pushed them to Microsoft's genuine sign-in page at microsoft.com/devicelogin. Entering the code there authorized the attacker's session rather than a device, sidestepping multifactor authentication. Microsoft warned that the resulting access "could persist even after a password reset if the associated sessions and tokens were not also revoked."

What set the service apart was what happened next. "At the center of the service was an AI-style chatbot that could analyze a victim's inbox and help criminals identify trusted relationships, payment authorizations, and sensitive responsibilities," said Steven Masada, associate general counsel at Microsoft's Digital Crimes Unit, adding that the tool could also draft messages impersonating trusted contacts. Trevor Hilligoss, chief intelligence officer at partner firm SpyCloud, said the platform read compromised mailboxes "in more than twenty languages to find the conversations worth hijacking." Access cost $1,500 up front plus a $500 monthly fee.

Microsoft dates the platform's emergence to February 2026; The Hacker News reports that Huntress first documented it in March. SpyCloud said it recovered phished data covering 8,708 unique victim accounts across 6,585 corporate email domains in 79 countries, with the earliest captures on February 18, 2026. Coinbase, another partner in the action, said it traced roughly $1.1 million in platform revenue across four Tron addresses between October 2025 and June 2026. Victim activity was concentrated in the United States, Canada, the United Kingdom, Australia, India and France, in wholesale distribution, construction, financial services, real estate, higher education and healthcare.

Neither Microsoft nor its partners published an estimate of what victims lost, and the published accounts do not name the two arrested men or describe any charges. Microsoft says it is tracking the developers behind the service as Storm-2992, and it recommends that organizations block the device code sign-in flow wherever it is not needed, narrowing any exception to specific Teams device accounts. Other partners named in the takedown included Health-ISAC, Cloudflare, OpenAI, Railway, the Shadowserver Foundation and TRM Labs.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.