Full Report
Used by crims to compromise 12K+ email inboxes across 10K+ global orgs
Analysis Summary
# Incident Report: Disruption of the "EvilTokens" AI-Enabled Phishing Service
## Executive Summary
A global law enforcement and private-sector coalition, led by Microsoft and the UK Metropolitan Police, disrupted "EvilTokens," a sophisticated Phishing-as-a-Service (PhaaS) platform. The service utilized AI-driven chatbots to bypass Multi-Factor Authentication (MFA) and automate the exploitation of compromised accounts, impacting over 10,000 organizations. The operation resulted in the arrest of two suspected administrators and the seizure of over 200 malicious domains.
## Incident Details
- **Discovery Date:** Approximately March 15, 2026 (beginning of intensive monitoring)
- **Incident Date:** Service emerged February 2026; Law Enforcement action September 18, 2026
- **Affected Organizations:** 10,000+ global organizations (including Healthcare sector)
- **Sector:** Cross-sector (Global)
- **Geography:** Global impact; arrests made in London, UK; legal action in Virginia, USA
## Timeline of Events
### Initial Access
- **Date/Time:** February 2026 (Service launch)
- **Vector:** Device-code phishing kits
- **Details:** Attackers lured victims into using Microsoft device-code authentication, allowing the service to intercept tokens and bypass MFA.
### Lateral Movement
- **Details:** Once the initial Microsoft 365 account was compromised, attackers moved laterally across the organization's cloud applications (Outlook, SharePoint, etc.) using the hijacked authentication tokens.
### Data Exfiltration/Impact
- **Impact:** Compromise of 12,000+ email inboxes. AI chatbots were used to analyze inbox contents instantly to identify high-value targets and craft convincing impersonation emails for Business Email Compromise (BEC).
### Detection & Response
- **March 2026:** Microsoft observed 10–15 distinct campaigns launching every 24 hours.
- **September 18, 2026:** London’s Metropolitan Police arrested two suspected admins (ages 32 and 38).
- **September 2026:** Microsoft and Health-ISAC obtained a court order to seize 50 websites and disable 150+ supporting domains.
## Attack Methodology
- **Initial Access:** Device-code phishing (bypassing MFA via token theft).
- **Persistence:** Silent authentication to Microsoft 365 applications using stolen tokens.
- **Privilege Escalation:** Not explicitly detailed, but involved gaining "trusted contact" status via hijacked accounts.
- **Defense Evasion:** Use of legitimate Microsoft authentication flows (device-code) to appear as authorized traffic.
- **Credential Access:** Theft of OAuth/Authentication tokens rather than traditional passwords.
- **Discovery:** **AI-Enabled Reconnaissance.** An AI chatbot analyzed the victim's inbox to identify contacts and sensitive financial threads.
- **Lateral Movement:** Cloud-based movement via authenticated application tokens.
- **Collection:** Automated scanning of email content and attachments.
- **Exfiltration:** Exfiltration of sensitive communications and financial data.
- **Impact:** Financial fraud, BEC, and unauthorized access to 10k+ organizations.
## Impact Assessment
- **Financial:** High potential for loss via automated BEC fraud, though specific figures are not disclosed.
- **Data Breach:** Compromise of 12,000+ private email inboxes across global sectors.
- **Operational:** Disruption to 10,000+ organizations; necessity for large-scale password/token resets.
- **Reputational:** Significant risk for affected organizations, particularly in the healthcare sector.
## Indicators of Compromise
- **Network Indicators:**
- 50+ seized domains (URLs not listed but related to EvilTokens infrastructure).
- 150+ disabled supporting domains.
- **Behavioral Indicators:**
- Unusual device-code authentication requests from unrecognized locations.
- Rapid, automated analysis of inbox contents following a login.
- Requests to change payment information immediately following an MFA-bypass event.
## Response Actions
- **Containment:** Domain seizures via US District Court for the Eastern District of Virginia.
- **Eradication:** Shutdown of EvilTokens platform infrastructure by Microsoft, Cloudflare, OpenAI, and others.
- **Recovery:** Microsoft notified all affected customers and assisted in remediating compromised accounts.
## Lessons Learned
- **AI Acceleration:** Criminals are now using end-to-end AI to reduce the "dwell time" between compromise and exploitation from days to minutes.
- **MFA Vulnerability:** Standard MFA is no longer a silver bullet; token-theft and device-code phishing are highly effective against traditional protections.
- **Collaboration Works:** The partnership between big tech (Microsoft), non-profits (Health-ISAC), and law enforcement (Met Police) is essential for disrupting PhaaS.
## Recommendations
- **Authentication Security:** Implement phishing-resistant MFA (e.g., FIDO2 keys) where possible.
- **Verification Protocols:** Independently verify all requests for fund transfers or bank detail changes via a "trusted second channel" (e.g., a phone call).
- **Monitoring:** Implement alerting for "Device Code" authentication flows, especially if they originate from unexpected IP ranges or geographic locations.
- **Inbox Auditing:** Monitor for rapid mailbox exports or unusual automated searching within email accounts.