Microsoft disrupts EvilTokens—why a password reset may not end stolen access

SNACK: 3-line summary

  • Microsoft disrupted EvilTokens, linking the service to more than 12,000 compromised inboxes across over 10,000 organizations.
  • Its device-code phishing used Microsoft’s legitimate sign-in page, and access could persist after a password reset unless associated sessions and tokens were revoked.
  • Verify payment changes and unusual fund-transfer requests through a trusted second channel, even when the email appears to come from someone you know.

Microsoft has disrupted EvilTokens, an AI-enabled service that helped criminals gain email access and turn inbox conversations into fraud opportunities. The September 22 announcement carries a practical warning: resetting a password may not end unauthorized access if the associated sessions and tokens remain active.

Microsoft Digital Crimes Unit official EvilTokens disruption visual
Official visual for the Microsoft Digital Crimes Unit disruption of EvilTokens. Image: Microsoft.

Snackgirls react

AIKO: A new password can look like a clean break while an old session still has access. I’d want the recovery process to account for both—not stop at the password change.

Nea: A message that knows the people and invoices I recognize would be harder to question. I’d still want to hear from the person through a separate, trusted channel before moving any money.

A real Microsoft sign-in page, an attacker’s request

EvilTokens used device-code phishing. Victims were tricked into entering an authentication code on Microsoft’s legitimate sign-in page, completing the normal sign-in process and granting account access without revealing their password. The attack did not depend on a fake login page stealing credentials.

If you suspect this kind of compromise, use your organization’s account-recovery process to revoke the associated sessions and tokens as well as reset the password. Microsoft warned that access could otherwise persist after the reset.

EvilTokens interface analyzing stolen inbox data for targets and attack opportunities
EvilTokens AI analysis screen identifying targets and attack opportunities in a compromised inbox. Image: Microsoft.

Stolen conversations became a guide to impersonation

Once inside an account, EvilTokens’ AI tools could summarize and translate messages, surface financial discussions, map organizational roles and identify trusted relationships. Preset prompts helped locate wire-transfer conversations and vendor invoices, identify people who move money, and suggest whom to impersonate.

That makes a familiar sender or convincing knowledge of a business relationship an insufficient reason to approve a payment request. Microsoft advises independently verifying changes to payment details, redirected funds and unusual transactions through a trusted second channel.

EvilTokens dashboard listing tools for account compromise and fraudulent email operations
EvilTokens tools dashboard combining account-compromise and fraudulent-email operations. Image: Microsoft.

50 websites seized, more than 150 additional domains disabled

Microsoft linked EvilTokens to more than 12,000 compromised inboxes across over 10,000 organizations worldwide following its February 2026 launch. Microsoft and its partners seized 50 operating websites and disabled more than 150 additional domains supporting the service.

Microsoft also notified affected customers, helped remediate compromised accounts and shared intelligence with defenders and investigators. This was its Digital Crimes Unit’s 40th court-authorized disruption, and its first against an end-to-end AI-enabled cybercrime service.

The infrastructure is disrupted; the investigation continues

The Metropolitan Police Service’s cybercrime team arrested two men in the United Kingdom on September 11 on suspicion of offenses connected with the alleged operation. Both were released on police bail while the investigation continues.

Microsoft warned that the operating model demonstrated by EvilTokens would not disappear with this action. Ending unauthorized account access and independently checking sensitive payment requests remain necessary safeguards even after the service’s infrastructure has been disrupted.

Sources and checked date: Microsoft On the Issues · September 23, 2026

Related hashtags
#GameSunakku #Microsoft #EvilTokens #Cybersecurity #DeviceCodePhishing #EmailSecurity

Game Sunakku에서 더 알아보기

지금 구독하여 계속 읽고 전체 아카이브에 액세스하세요.

계속 읽기