Back to all lessons
Awareness Lessons
3 weeks ago

AI-Powered Device-Code Phishing Compromises 12,000 Inboxes

The EvilTokens service exploited the OAuth device-code authentication flow — a legitimate mechanism designed for input-limited devices — to trick users into granting persistent access tokens to attackers without ever capturing a password. Once tokens were harvested, an embedded AI chatbot autonomously analyzed victim inboxes, mapped trusted relationships, and generated highly convincing impersonation messages to propagate fraud further. This attack demonstrates that modern phishing has evolved beyond credential theft into AI-assisted, token-based account takeover that bypasses MFA entirely. The scale of 12,000 compromised inboxes underscores how quickly automated, platform-as-a-service cybercrime tools can amplify a single attacker's reach. Organizations that rely solely on password-based or traditional MFA defenses are increasingly exposed to token-hijacking techniques.

Tactical Insight

Immediate actions

  • Block or restrict the OAuth device-code authentication flow (grant type `urn:ietf:params:oauth:grant-type:device_code`) in your identity provider for users who do not require it.
  • Audit existing OAuth application consents and revoke any suspicious or unrecognized token grants across all mailboxes.
  • Enable Conditional Access policies that flag or block authentication requests originating from unfamiliar devices or unexpected geolocations.

Security awareness measures

  • Train users to recognize device-code phishing lures (e.g., unsolicited prompts asking them to visit a URL and enter a code) and report them immediately.
  • Run simulated device-code phishing exercises to measure and improve employee recognition rates.

Long-term improvements

  • Enforce phishing-resistant MFA methods (FIDO2/passkeys) as a baseline, reducing reliance on token flows susceptible to interception.
  • Implement continuous monitoring and anomaly detection on mailbox access patterns to catch AI-driven lateral phishing campaigns early.
  • Establish a formal OAuth application governance program that requires periodic review and least-privilege scoping of all third-party app integrations.