Microsoft has disrupted infrastructure associated with EvilTokens after obtaining authority from a US federal court. Axios reports that the service compromised more than 12,000 email inboxes across 10,000 organisations, including companies in finance, healthcare, property and education.
The reported technique used device-code phishing. This can trick a victim into authorising an attacker-controlled session, allowing the criminal to obtain tokens without stealing a conventional password. Once inside an email account, an attacker can impersonate executives, redirect payments, steal data or move deeper into connected systems.
The AI element matters because criminal services can automate targeting, message creation and operational support. EvilTokens reportedly charged an initiation fee and monthly subscription, lowering the expertise needed to run campaigns at scale.
A court-backed takedown removes infrastructure; it does not automatically invalidate every stolen token or eliminate copycat services. Organisations still need rapid token revocation, controls around device-code authentication, behavioural detection and strong monitoring of new application consent. The useful enterprise lesson is that identity has become the control plane for both human and AI-assisted attacks.
