Microsoft's Digital Crimes Unit, working with Coinbase, Cloudflare, OpenAI and other partners, dismantled EvilTokens, a subscription phishing service Microsoft says compromised more than 12,000 email inboxes across over 10,000 organizations worldwide [1]. Sold on Telegram for $1,500 up front plus $500 a month, the service ran on device-code phishing, a technique that steals a working, signed-in session instead of a password and can also be aimed at Apple and Google accounts [1].
Background
Microsoft explains that the technique abuses a legitimate sign-in method called the OAuth device code flow, built for devices with no keyboard or browser to speak of, such as a smart TV or an office printer: the device shows a short code and a web address, a person types the code into their phone or laptop, and the device signs in without a password ever being entered on it [1].
Findings
Attackers turn that same flow against people. Microsoft's writeup describes a phishing page that quietly requests a fresh, real device code from Microsoft's own identity service the moment it is opened, and displays that code next to a "Continue with Microsoft" button [1]. Typing the code into the genuine microsoft.com sign-in page, as the attacker's page instructs, approves the attacker's device, not the victim's. The attacker's software checks every few seconds for up to 15 minutes to see whether this has happened, and EvilTokens copied the code straight to the clipboard to speed that up [1]. Once approved, the attacker receives a valid, signed-in session, with no password stolen and no software installed, and multi-factor authentication is sidestepped because, from the account's point of view, a real device code was legitimately approved [1].
EvilTokens first appeared in February 2026 and grew, per Microsoft, into one of the most widely used phishing-as-a-service platforms by offering 44 phishing email and page templates, automated infrastructure on services like Vercel and Cloudflare Workers, and a Telegram bot for customer support; Microsoft tracks the operator as Storm-2992 [1]. After a mailbox was compromised, Microsoft says its AI features would sift through the stolen inbox, pick out messages about payments, map who reported to whom, and draft follow-up messages impersonating a trusted contact to push a fraudulent payment through, as The Hacker News reported [2].
Acting on a court order from the US District Court for the Eastern District of Virginia, Microsoft says it seized around 50 websites tied to the service and disabled more than 150 more, working with Cloudflare, OpenAI, Coinbase, SpyCloud, TRM Labs, the Shadowserver Foundation and Health-ISAC [1]. Coinbase traced roughly $1.1 million in cryptocurrency payments to the service across more than 1,000 deposits, and London's Metropolitan Police arrested two men, aged 32 and 38, in connection with running the site [2]. TechSpot's coverage adds that victims were concentrated in the US, Canada, the UK, Australia, India and France, hitting distributors, construction firms, banks, universities and hospitals particularly hard [3].
Implications for Mac users
Direct exposure applies to anyone who uses a Microsoft account, work or personal, and encountered one of these phishing pages, most likely through an email about a document to sign, a password expiring, or a business proposal. The technique itself is not Microsoft-specific: Google, Apple and other services offer their own version of signing in by entering a code on another device, and the same social-engineering move works against any of them. Using a Mac does not provide protection here, because the attack targets an account in the cloud, not the computer itself.
Recommendations
- Never enter a sign-in code unless that sign-in was started personally, moments earlier, on the device being held; a code that arrives after clicking a link in an email or chat is the scam itself.
- Be suspicious of any page that pushes toward "sign in on another device" or "continue with Microsoft/Google" right after clicking a link, especially from an unsolicited email about invoices, document signing or password expiry.
- Slow down under urgency: EvilTokens’ templates leaned on deadlines such as an expiring password, a contract to sign, or an overdue payment.
- Periodically check active sessions and devices in Microsoft, Google or Apple account settings, and sign out anything unrecognised.
- Where offered, use a hardware security key instead of a code or app-based approval, since it checks the actual website address rather than a code copied by hand.
Relevance to FireAI
Device-code phishing is not primarily a malicious app connecting from a Mac. It happens through a person’s own actions on a real, legitimate Microsoft or Google login page, and the account takeover itself happens on that company’s servers, not on the machine being used. FireAI cannot see what happens inside Microsoft’s or Google’s identity systems, cannot tell that a code was phished rather than legitimate, and cannot revoke a stolen session or token on an account; only the account provider’s own security settings and a person’s own vigilance can do that part.
Where FireAI can still help, modestly: its threat-intelligence lists can block a known phishing domain if reached through a link, and Investigate or the world map can help notice a browser suddenly reaching an unfamiliar server. That is a useful extra layer, not the fix; the actual defence against this scam is refusing to enter a code that was not requested.
Limitations
Reporting on the arrest dates varies: Microsoft-linked coverage places the London arrests between 11 and 18 September, so the exact date is unconfirmed [2]. The roughly 12,000 compromised inboxes are all tied to EvilTokens targeting Microsoft accounts specifically; none of the sources documents a confirmed device-code phishing case against an Apple or Google account through this particular service, so that risk is described here as a property of the technique in general, not as something this takedown found evidence of [1].
Try FireAI, by HisnLabs free for 17 days.