Phishing and scams

EvilTokens: device-code phishing and more than 12,000 compromised inboxes

Microsoft details a platform abusing device-code sign-in and using AI to tailor lures and analyse compromised mailboxes.

Conceptual illustration: EvilTokens: device-code phishing and more than 12,000 compromised inboxes
Conceptual illustration · SecurCheck

What is confirmed

Microsoft attributes more than 12,000 compromised inboxes across over 10,000 organisations since February 2026 to EvilTokens.

The service tricks victims into entering a legitimate device code to authorise an attacker's session; Microsoft coordinated disruption of its infrastructure.

What it means

Multifactor authentication does not stop this scenario if a user authorises a session started by the attacker.

A compromised mailbox can then be used to read threads, create hiding rules and prepare payment fraud.

What to do

Never enter a sign-in code received by email to view an invoice or shared document.

At work, revoke suspicious sessions and tokens, inspect mailbox rules and restrict this authentication flow if unnecessary.

Check a suspicious sign

Approved an unexpected sign-in code or noticed unusual activity? Check your account access and revoke suspicious sessions.

Sources

  1. Microsoft Threat Intelligence — 22 septembre 2026