Back to advisories

Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud

EvilTokens, a phishing-as-a-service platform, compromised over 12,000 Microsoft customer email accounts across 10,000+ organizations by stealing session tokens for business email compromise and financial fraud. The platform used AI-driven phishing to enable attackers to conduct unauthorized wire transfers and financial crimes, resulting in $1.7M in confirmed fraud losses. Two operators were arrested in the UK, but the threat actors behind compromised accounts remain active.

CRITICALAdvisorySep 24, 2026
Action required
Hunt for anomalous authentication patterns: review Azure AD sign-in logs for impossible travel, unusual locations, off-hours access, and token usage from unfamiliar IPs. Cross-reference with email forwarding rules, inbox rules, and mailbox delegation changes. Prioritize accounts in finance, HR, and executive roles.
Affected products
MicrosoftEvilTokensCoinbase