Threats · 46m ago

Microsoft Cuts Off EvilTokens BEC Service

Microsoft and partners disrupted EvilTokens, a device-code phishing service linked to more than 12,000 compromised inboxes across over 10,000 organizations, and UK police arrested two suspected operators tied to Storm-2992. Microsoft says the service was built to turn stolen mailbox access into business email compromise at scale.

The kit used OAuth device-code phishing to win a victim’s login session, then an AI chatbot read the real inbox to identify trusted contacts, payment approvals, and other details worth exploiting. That let attackers tailor fraud after they were already inside, and it also supported persistence by keeping access to the mailbox itself.

For Microsoft 365 and similar inbox-driven workflows, the lasting exposure is not just the lure that got clicked. Once an attacker has mailbox context and session access, finance and approval chains become part of the attack surface, and filtering alone does not contain what follows.

Timeline

Sources

7 sources covering this story

Entities

Part of the PlainSec briefing for 2026-09-22

Editions

Related stories