Microsoft leads takedown of EvilTokens phishing service, two UK men arrested
Microsoft's Digital Crimes Unit, working with Health-ISAC, law enforcement, and SpyCloud, dismantled the infrastructure behind EvilTokens, a phishing-as-a-service platform that had compromised over 12,000 Microsoft accounts across more than 10,000 organizations. The UK's Metropolitan Police arrested two men, aged 32 and 38, suspected of administering the site, following raids in Canary Wharf and Nine Elms; both were released on bail.
GoKawiil's interpretation of the reporting above, not reported fact.
EvilTokens pioneered large-scale abuse of device-code authentication, a method that lets attackers bypass multi-factor authentication without stealing credentials directly, and its AI-powered lure customization made it especially effective. Its rise since February helped spark a broader wave of similar phishing platforms, with at least ten services offering device-code phishing by April, showing how quickly criminal tooling innovations spread once proven successful.
- EvilTokens compromised over 12,000 Microsoft accounts at 10,000+ organizations before disruption.
- The platform's device-code phishing technique bypassed MFA protections without needing stolen credentials.
- Two UK suspects were arrested in a coordinated effort involving Microsoft, police, and SpyCloud.
YubiKey 5C NFC Security Key — With phishing-as-a-service kits like EvilTokens targeting Microsoft accounts through stolen tokens and session hijacking, hardware-backed authentication is one of the strongest defenses available. A YubiKey adds a physical security layer that phishing pages and device-code tricks can't easily bypass, making it a smart upgrade for anyone relying on Microsoft 365 or other cloud accounts.
See YubiKey 5C NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.Source: bleepingcomputer.com, 2026-09-22
Published there as: “EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.