How EvilTokens Used AI to Breach 12,000 Corporate Inboxes
Microsoft dismantled an AI-powered phishing service that breached more than 12,000 corporate inboxes in eight months, revealing how attackers are automating corporate email compromise.
In September, Microsoft took down EvilTokens, an operation that had compromised more than 12,000 email inboxes across over 10,000 organizations worldwide in just eight months. The takedown, made possible by a coalition that included Cloudflare, Coinbase, and OpenAI, underscores a troubling shift in how cybercriminals are weaponizing artificial intelligence to make sophisticated email attacks more accessible and profitable.
EvilTokens did not require breakthrough technology—rather, it applied AI to simplify the complex work of email compromise into a commoditized service. The operation charged a $1,500 initiation fee and $500 monthly subscription, selling access through Telegram. For that price, criminals gained not just technical infrastructure but an AI-powered partner that could perform work that traditionally required days of manual investigation in a matter of hours. The service attracted enough criminal customers that device-code phishing attacks tied to EvilTokens grew rapidly in the months after its February 2026 launch.
How the Attack Leveraged a Standard Authentication Method
EvilTokens exploited the OAuth 2.0 device authorization flow, a legitimate feature of Microsoft’s identity system designed for devices that lack traditional keyboards or screens—smart televisions, printers, and other internet-connected equipment. The attack began with a phishing email containing a malicious URL or code, typically delivered through generic social engineering or targeted campaigns. When victims clicked, background scripts automatically generated a device code and directed them to the authentic microsoft.com/devicelogin page.
At that point, the attack appeared entirely routine. Users entered the code they were shown on their screen, and if they were not already logged into their Microsoft account, they entered their credentials and any multifactor authentication codes their organization required. What they did not know was that the attacker’s application was simultaneously receiving access tokens and refresh tokens that granted persistent inbox access.
This method had a critical advantage for attackers: the access could persist even after a victim changed their password, provided the compromised tokens and sessions remained active. Cleanup required administrators to revoke not just the password but the associated sessions and tokens as well—a step organizations often missed. Additionally, EvilTokens operators registered new devices for persistent access, created hidden inbox rules to suppress alerts about suspicious activity, and monitored payment threads to identify opportunities for fraud.
The device code flow is used legitimately by many organizations and applications. Its vulnerability was not a flaw but rather an unintended consequence of how threat actors could weaponize its normal operation at scale with AI assistance.
EvilTokens by the Numbers
The phishing service compromised more than 12,000 inboxes across more than 10,000 organizations in eight months, from February through September 2026. The operation cost criminals $1,500 to join and $500 per month. Device-code phishing attacks tied to the service grew rapidly in the months after its February 2026 launch, indicating rapid adoption of the technique. The takedown seized 50 websites and disabled more than 150 domains.
The Role of AI in Automating Email Investigation
Once inside an inbox, EvilTokens deployed an AI chatbot that transformed raw email into actionable intelligence. The platform could summarize and translate messages, map organizational roles, identify trusted relationships, and surface financial conversations. It provided attackers with 44 customized email templates and used AI to draft impersonation messages tailored to the victim organization. The platform also included a control panel where criminals could build and manage phishing campaigns, customize landing pages, configure domains, track victims, and manage stolen authentication tokens.
The platform included preset prompts designed to locate specific targets: those discussing wire transfers, handling vendor invoices, or identified as the organization’s money movers. When the chatbot identified a vulnerable relationship—say, an employee authorizing payments to a trusted vendor—it recommended fraud strategies, including specific messages to impersonate that trusted contact. Rather than attackers having to write convincing impersonation emails themselves, the AI generated them based on the victim’s role, communication style, and organizational context.
This automation compressed what might otherwise take attackers days of inbox analysis into hours of work. A task that previously required skilled operators and substantial effort—manually reading through emails, identifying key relationships, understanding payment processes, and drafting convincing messages—became something a less experienced criminal could accomplish by following the platform’s recommendations. By lowering the technical and time barriers, EvilTokens made email compromise accessible to criminals with minimal expertise.
The service functioned less as a tool and more as a complete attack platform: identify the victim, analyze their relationships, recommend the exploit, and draft the message. EvilTokens itself was sold for cryptocurrency payments on the Tron blockchain, and Coinbase, as part of the takedown coalition, traced approximately $1.1 million in platform revenue across four Tron addresses, which ultimately helped investigators identify the operation’s operators.
Which Organizations and Sectors Were Hit
The more than 12,000 compromised inboxes spanned over 10,000 organizations, concentrated in six countries: the United States, Canada, the United Kingdom, Australia, India, and France. The diversity of targets reflected the breadth of the service’s appeal. EvilTokens operators were not targeting specific high-value victims; instead, they were running a volume-based business model, attacking thousands of organizations broadly.
Victim organizations operated in wholesale distribution, construction, financial services, real estate, higher education, and healthcare. These sectors share a common vulnerability: they process regular payments, contain trusted vendor relationships, and have hierarchies of financial approval. An attacker with access to the right inbox—a finance manager, a procurement officer, a department head—could impersonate trusted contacts and redirect payments, often without triggering organizational suspicion.
The platform’s AI was particularly effective at identifying these vulnerable relationships and payment processes. Rather than searching for executives or high-profile targets, the AI would flag accounts that received vendor payment requests or approval authorities. This approach was more reliable than targeting senior leadership, since it directly identified individuals who controlled money movement.
Criminals with no special expertise can now launch sophisticated, personalized attacks at scale through AI-assisted services.
How the Takedown Unfolded
Microsoft worked with partners including Health-ISAC to build the case for court action. With authorization from the U.S. District Court for the Eastern District of Virginia, the coalition took action. Microsoft’s legal intervention seized 50 websites and disabled more than 150 additional domains that supported the operation’s infrastructure. Each partner in the coalition brought specific capabilities: Cloudflare’s expertise in domain and infrastructure disruption, Coinbase’s ability to trace cryptocurrency transactions, and others’ specialized knowledge.
The investigation also led to law enforcement action. The Metropolitan Police Service in London arrested two men, aged 32 and 38, on September 11, 2026. Their arrest followed intelligence shared by Microsoft investigators and coordination among multiple law enforcement agencies. The men’s arrest suggested the operation had clear operators based in the United Kingdom, though the service marketed itself globally and attracted criminals worldwide.
The takedown required coordination that went beyond a single company or agency. Microsoft employed reverse engineering and AI tools to investigate EvilTokens, illustrating that defensive innovation must match offensive capabilities. Health-ISAC, a global non-profit information sharing organization focused on the healthcare sector, brought sector-specific knowledge since healthcare organizations were among those targeted. The involvement of multiple private companies, government agencies, and international law enforcement demonstrated that disrupting modern cybercrime required cooperation across organizational and national boundaries.
What This Signals for Corporate Email Security
The EvilTokens disruption revealed a maturing ecosystem of AI-assisted cybercrime. The operation did not invent new attack methods—device code phishing had been documented before. Instead, it packaged existing techniques alongside automation and intelligence tools, then sold the combination as a service to any criminal willing to pay. The rapid growth in device-code phishing attacks tied to EvilTokens in the months after its February 2026 launch showed that criminals quickly adopted the service once it became available.
This commoditization has measurable effects: criminals with no special expertise can now launch sophisticated, personalized attacks at scale. The platform’s 44 email templates and AI-assisted message crafting meant each victim might receive a message tailored to their organization and relationships. The personalization increased the likelihood of success compared to generic phishing campaigns.
For organizations, the threat signals the need to monitor and revoke tokens and sessions, not just passwords. It also underscores the value of restricting which applications can access email systems and implementing stronger verification for payment-related email requests. The more than 12,000 compromised inboxes represent persistent access that criminals maintained over time, meaning the full scope of damage—diverted payments, stolen data, compromised relationships—may not be fully known.
The takedown also illustrates a fundamental challenge: AI has become integral to both attack and defense. Microsoft used AI tools to investigate and disrupt EvilTokens, while the criminals used AI to run the operation. This symmetry suggests that defensive investments must evolve at the same pace as offensive capabilities. Organizations cannot rely on traditional email security approaches if attackers are using AI to generate personalized messages and identify vulnerable targets at scale.
Photo: jaydeep_ · CC0 · via Wikimedia Commons




