​Global Enforcement Action Disrupts Device-Code Phishing Service Targeting 10,000 Organizations

Rinky Rai
By Rinky Rai - A freelance journalist
5 Min Read

A multinational cyber operation led by Microsoft has disrupted the infrastructure of EvilTokens, a commercially packaged phishing service that compromised more than 12,000 email inboxes across over 10,000 organizations worldwide. Authorized by a United States court order, the enforcement action resulted in the seizure of 50 websites and the disabling of more than 150 related domains used to orchestrate device-code phishing campaigns. The operation brought together key industry partners including Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, Health-ISAC, The Shadowserver Foundation, and TRM Labs. Two men aged 32 and 38 were arrested in the United Kingdom on September 11, 2026, in connection with the illicit operation, which Microsoft tracks internally under the designation Storm-2992.

Device-Code Phishing Bypasses Standard Password Defenses

​First documented by cybersecurity researchers in March 2026, EvilTokens operated as a phishing-as-a-service platform that provided subscribers with ready-made tools to hijack enterprise email accounts without requiring deep technical knowledge. The underlying mechanism manipulated Microsoft’s legitimate OAuth 2.0 device authorization workflow. Unsuspecting users were lured through deceptive emails, HTML files, or PDF attachments to landing pages that displayed a unique device verification code. The victims were then directed to enter that code directly into genuine Microsoft login portals, inadvertently authorizing token generation for the attacker.

​Because users completed authentication on legitimate login pages, they were never prompted to submit their credentials to fraudulent forms, enabling attackers to acquire active session tokens directly. Once authenticated, the operators established persistent access by creating stealthy forwarding rules in targeted mailboxes and registering rogue devices. Investigators observed that standard password resets failed to dislodge the attackers, as unauthorized access persisted until security administrators explicitly revoked all active session tokens. Data contributed by SpyCloud revealed 8,708 unique accounts compromised across 6,585 corporate domains in 79 countries, with the highest concentration of victims situated in India, the United States, the United Kingdom, Canada, Australia, and France across industries such as healthcare, higher education, finance, real estate, and construction.

Integrated Artificial Intelligence Automates Financial Scams

​A distinguishing element of the platform was an integrated artificial intelligence chatbot configured to parse breached mailboxes for high-value targets. The system systematically analyzed internal email chains to identify staff authorized to execute wire transfers, inspect vendor billing documents, and uncover routine payment workflows. Using specialized preset prompts, the software mapped organizational hierarchies, located ongoing discussions regarding wire transactions, and identified trusted executives whose email personas could be effectively imitated in subsequent fraud attempts.

​The automated system also translated and summarized internal communications, drafting deceptive messages designed to blend seamlessly into existing professional correspondence. Investigators noted that substantial portions of the underlying EvilTokens software framework had been developed with AI assistance, lowering technical barriers for cybercriminals seeking to conduct business email compromise schemes at scale. In addition, the operators disguised malicious network traffic by leveraging reputable cloud infrastructure services, including Vercel, Cloudflare Workers, and AWS Lambda, while employing fake CAPTCHA tests and multiple redirect stages to evade corporate email security filters.

Commercial Platform Traced Across Cryptocurrency Networks

​EvilTokens operated as a structured commercial entity with tiered software offerings. Its catalog featured the B2B Sender priced at $600, the SMTP Sender at $1,000, and the Office 365 Capture Link, which hosted the primary device-code exploitation kit, at $1,500. Users were further required to pay a recurring monthly subscription fee of $500 to retain administration panel access and maintain active phishing kits.

​Financial tracking conducted by Coinbase identified approximately $1.1 million in platform-generated revenue moving through four Tron addresses between October 2025 and June 2026. Analysts documented more than 1,000 separate customer payments originating from over 700 distinct cryptocurrency addresses, illustrating the widespread commercial adoption of the service prior to coordinated law enforcement and private sector intervention.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected