The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

In September 2026, Microsoft's Digital Crimes Unit successfully disrupted the EvilTokens phishing-as-a-service platform that had compromised over 12,000 Microsoft accounts across 10,000+ organizations since February 2026. The platform specialized in device-code phishing attacks that bypassed multi-factor authentication by abusing OAuth 2.0 device authorization flows, targeting wholesale distribution, construction, financial services, healthcare, and education sectors. Two suspected administrators were arrested in the UK, though the threat remains active with affiliates creating clone platforms.

This incident highlights the escalating sophistication of phishing-as-a-service operations and the growing threat of device-code authentication abuse, which has seen a 37x surge in attacks as cybercriminals adopt AI-powered tools for enhanced targeting and evasion.

Why This Matters Now

Device-code phishing represents a critical evolution in identity-based attacks that bypass traditional MFA protections, with multiple PhaaS platforms now offering these capabilities at scale, requiring immediate organizational review of authentication policies and device-code flow configurations.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

EvilTokens abused Microsoft's OAuth 2.0 device authorization flow, tricking users into authenticating legitimate device codes through phishing lures that directed them to Microsoft's real login portal.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely constrain this OAuth token abuse campaign by limiting cross-organizational access paths and restricting lateral movement between cloud workloads, potentially reducing the blast radius from 10,000+ organizations to segmented environments.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Cloud-native security policies would likely detect and limit the scope of OAuth token abuse by monitoring authentication flows and restricting access to cloud resources based on behavioral analysis.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Identity-aware segmentation policies would likely constrain privilege escalation by limiting compromised account access to specific network segments and reducing visibility into organizational structures across cloud environments.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Workload-to-workload security controls would likely limit lateral movement by restricting east-west traffic flows between cloud services and preventing unauthorized access to additional organizational resources and mailboxes.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Unified multicloud monitoring would likely detect and constrain command and control activities by providing visibility across cloud platforms and identifying suspicious communication patterns between compromised infrastructure components.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Controlled egress policies would likely reduce the scope of data exfiltration by monitoring and restricting outbound data flows from compromised cloud workloads and limiting access to sensitive business communications.

Impact (Mitigations)

Residual business disruption would likely be contained to initially compromised segments rather than spreading across wholesale distribution, construction, financial services, real estate, higher education, and healthcare sectors at scale.

Impact at a Glance

Affected Business Functions

  • Email Communications
  • Authentication Systems
  • Business Email Operations
  • Financial Transaction Processing
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $2,500,000

Data Exposure

Compromised authentication tokens for over 12,000 Microsoft 365 accounts across 10,000+ organizations, including access to corporate email communications, wire transfer information, pending invoices, and executive correspondence. Business email compromise campaigns targeting financial transactions and sensitive corporate communications.

Recommended Actions

  • • Implement Zero Trust Segmentation to prevent lateral movement between compromised accounts and limit access to high-value organizational resources
  • • Deploy Egress Security & Policy Enforcement to block unauthorized data exfiltration and detect suspicious outbound communication patterns to external domains
  • • Enable Multicloud Visibility & Control to monitor OAuth token usage patterns and detect anomalous Microsoft Graph API access across cloud environments
  • • Utilize Threat Detection & Anomaly Response capabilities to baseline normal authentication flows and alert on device-code authentication abuse patterns
  • • Enforce Cloud Firewall (ACF) with URL filtering to block access to known phishing infrastructure and prevent communication with malicious redirect chains

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image