What is confirmed
Microsoft attributes more than 12,000 compromised inboxes across over 10,000 organisations since February 2026 to EvilTokens.
The service tricks victims into entering a legitimate device code to authorise an attacker's session; Microsoft coordinated disruption of its infrastructure.
What it means
Multifactor authentication does not stop this scenario if a user authorises a session started by the attacker.
A compromised mailbox can then be used to read threads, create hiding rules and prepare payment fraud.
What to do
Never enter a sign-in code received by email to view an invoice or shared document.
At work, revoke suspicious sessions and tokens, inspect mailbox rules and restrict this authentication flow if unnecessary.
Approved an unexpected sign-in code or noticed unusual activity? Check your account access and revoke suspicious sessions.

