Police arrested two men over a phishing service that skipped MFA on 12,000 Microsoft 365 inboxes
Cyber Security

Police arrested two men over a phishing service that skipped MFA on 12,000 Microsoft 365 inboxes

EvilTokens sold Microsoft 365 account takeover as a subscription, with an AI chatbot that read the victim's inbox and picked who to defraud. Microsoft seized 50 sites and the Met made two arrests. The sign-in trick it used still works on a tenant that has not blocked it.

22 September 20265 min read

Microsoft announced on 22 September 2026 that it had disrupted EvilTokens, a phishing-as-a-service platform that launched in February and was linked within months to more than 12,000 compromised email inboxes across over 10,000 organisations worldwide. Microsoft seized 50 websites used to run the service and disabled more than 150 supporting domains. In the UK, the Metropolitan Police Service's cybercrime team arrested two men, aged 32 and 38, on 11 September; both have been released on bail while the investigation continues. Microsoft says the UK was among the six countries with the highest concentration of victims, and that affected organisations ranged from wholesale distribution and construction to financial services, real estate, higher education and healthcare.

How it got past MFA without a password

EvilTokens ran on device code phishing. Device code sign-in is a legitimate Microsoft flow built for devices with no proper keyboard, such as smart TVs, printers and Teams meeting room kit: the device shows a short code, you type it into a browser on your phone or laptop, and the device is signed in. Microsoft's technical write-up describes what EvilTokens did with that. The victim clicked a link, was shown a code, often already copied to their clipboard, and a "Continue with Microsoft" button that led to the real microsoft.com/devicelogin page. Pasting the code authorised the attacker's session. If the victim was already signed in, they were not even asked for a password. Microsoft notes that the access "could persist even after a password reset if the associated sessions and tokens were not also revoked". The lures were bounced through redirects on legitimate cloud platforms, including Vercel, Cloudflare Workers and AWS Lambda, so the traffic looked like ordinary business cloud use to scanners. From mid-March Microsoft was seeing 10 to 15 distinct campaigns launch every 24 hours, its VP of security research told The Register.

What the AI did once it was in

The part Microsoft is most exercised about is what happened after the sign-in. EvilTokens included an AI chatbot that read the compromised mailbox and did the work a fraudster used to do by hand: summarising and translating messages, surfacing financial conversations, mapping who reports to whom, identifying trusted relationships and recommending targets. Preset prompts offered to find wire-transfer discussions, identify the organisation's "money movers", locate supplier invoices and pick the best people to impersonate. The service was sold through Telegram for a 1,500 dollar initiation fee and a recurring 500 dollar subscription, and Microsoft's investigators found evidence that large parts of it had been "vibe coded" with AI. Steven Masada of Microsoft's Digital Crimes Unit summed up the lesson for organisations: assume that once an inbox is compromised, criminals may understand its contents "in minutes, not days".

The fix is a setting most small tenants have never looked at

Microsoft's guidance is to block device code flow wherever possible, using a Conditional Access policy in Entra ID, with an exception scoped to specific Teams device accounts if you have them. Beyond that it recommends Safe Links in Defender for Office 365, alerts on new inbox rules, which is how a fraudster hides the replies, and blocking legacy authentication. On a suspected compromise it says to revoke the user's sessions and, because that often leaves access tokens live for up to an hour, to disable the account temporarily even at the cost of a short disruption. Conditional Access is not in every Microsoft 365 plan, so the first question for whoever manages your tenant is whether you have it, and whether device code flow is blocked.

What this means for your business

Four things, in order. Ask whoever runs your Microsoft 365 whether device code flow is blocked, and if the answer is a blank look, that is your finding. Turn on an alert for new inbox rules. Understand that a password reset on its own does not evict an attacker; sessions have to be revoked, and Microsoft's advice is to disable the account briefly. And put the money control in place that works even when all of that fails: any request to change bank details, redirect a payment or approve an unusual transaction gets a phone call to a number you already had, never one from the email. EvilTokens' infrastructure is gone. The device code trick still works, and the next kit will use it.

#WEARECOBALT

Ready when you are.

Tell us what's slowing your business down. We'll tell you exactly how we'd fix it — plainly, with no obligation.