Device-code phishing service compromised 12,000 Microsoft inboxes

Device-code phishing service compromised 12,000 Microsoft inboxes. More than twelve thousand Microsoft inboxes across over ten thousand organizations were compromised through the EvilTokens phishing service.

This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Wednesday, September 23rd, 2026.

More than twelve thousand Microsoft inboxes across over ten thousand organizations were compromised through the EvilTokens phishing service. The platform abused legitimate device-code authentication. Victims were guided through a real Microsoft login, but the process authorized an attacker’s session instead of their own intended device. The service also used AI features to tailor phishing lures and analyze breached mailboxes for valuable conversations and relationships. Microsoft and its partners seized 50 websites and disabled more than 150 related domains.

Compromised inboxes can enable payment fraud, executive impersonation, and follow-on attacks against trusted customers and suppliers. The disruption should reduce EvilTokens activity, but competing services and clones remain available. For leaders, the key point is that a legitimate authentication page doesn’t guarantee the surrounding authorization request is safe. For defenders, device-code flow should be disabled wherever it isn’t operationally necessary, and unusual token use should be monitored. This campaign shows how attackers can abuse trusted identity processes rather than trying to break them. Block unnecessary device-code authentication and require phishing-resistant sign-in methods for sensitive accounts.

For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.

Device-code phishing service compromised 12,000 Microsoft inboxes
Broadcast by