Executive Summary
In September 2026, Microsoft's Digital Crimes Unit successfully disrupted the EvilTokens phishing-as-a-service platform that had compromised over 12,000 Microsoft accounts across 10,000+ organizations since February 2026. The platform specialized in device-code phishing attacks that bypassed multi-factor authentication by abusing OAuth 2.0 device authorization flows, targeting wholesale distribution, construction, financial services, healthcare, and education sectors. Two suspected administrators were arrested in the UK, though the threat remains active with affiliates creating clone platforms.
This incident highlights the escalating sophistication of phishing-as-a-service operations and the growing threat of device-code authentication abuse, which has seen a 37x surge in attacks as cybercriminals adopt AI-powered tools for enhanced targeting and evasion.
Why This Matters Now
Device-code phishing represents a critical evolution in identity-based attacks that bypass traditional MFA protections, with multiple PhaaS platforms now offering these capabilities at scale, requiring immediate organizational review of authentication policies and device-code flow configurations.
Attack Path Analysis
EvilTokens PhaaS leveraged device-code phishing to bypass MFA and compromise 12,000+ Microsoft accounts across 10,000+ organizations. Attackers used OAuth 2.0 device authorization flow abuse to obtain authentication tokens, escalated privileges through compromised accounts, moved laterally within organizations using Microsoft Graph API, maintained persistence through legitimate cloud infrastructure, exfiltrated sensitive data including wire transfer information and executive correspondence, and caused significant business disruption through sophisticated BEC campaigns targeting multiple industry sectors.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers used device-code phishing campaigns impersonating legitimate services like document-signing platforms, Microsoft services, and file-sharing providers to trick victims into authenticating through Microsoft's legitimate OAuth 2.0 device authorization flow, bypassing MFA protections
MITRE ATT&CK® Techniques
Phishing: Spearphishing Link
Multi-Factor Authentication Request Generation
Valid Accounts: Cloud Accounts
Brute Force
Email Collection: Remote Email Collection
Account Discovery: Email Account
Phishing: Spearphishing Attachment
Phishing: Spearphishing via Service
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Multi-Factor Authentication Implementation
Control ID: 8.2.1
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
DORA – ICT Risk Management Framework
Control ID: Article 8
CISA ZTMM 2.0 – Identity Verification and Authentication
Control ID: Identity Domain
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
GDPR – Security of Processing
Control ID: Article 32
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Device-code phishing bypassing MFA threatens financial institutions with business email compromise attacks targeting wire transfers and executive correspondence for fraudulent transactions.
Higher Education/Acadamia
Educational institutions face Microsoft 365 account compromise through AI-powered phishing targeting administrative communications and sensitive academic data across campus networks.
Health Care / Life Sciences
Healthcare organizations risk HIPAA violations through compromised Microsoft accounts enabling lateral movement and data exfiltration of protected health information systems.
Construction
Construction firms vulnerable to business email compromise attacks targeting bid proposals and partnership agreements through device-code authentication bypass techniques.
Sources
- EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accountshttps://www.bleepingcomputer.com/news/security/eviltokens-phaas-disrupted-after-compromising-12-000-microsoft-accounts/Verified
- EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accountshttps://www.bleepingcomputer.com/news/security/eviltokens-phaas-disrupted-after-compromising-12,000-microsoft-accounts/Verified
- Microsoft Digital Crimes Unit disrupts EvilTokens phishing-as-a-service operationhttps://blogs.microsoft.com/on-the-issues/2024/09/22/microsoft-digital-crimes-unit-eviltokens-takedown/Verified
- Device Code Authentication Flow - Microsoft Identity Platformhttps://docs.microsoft.com/en-us/azure/active-directory/develop/v2-oauth2-device-codeVerified
- SpyCloud Identity Threat Research - EvilTokens Campaign Analysishttps://spycloud.com/resource/eviltokens-campaign-analysis/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain this OAuth token abuse campaign by limiting cross-organizational access paths and restricting lateral movement between cloud workloads, potentially reducing the blast radius from 10,000+ organizations to segmented environments.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Cloud-native security policies would likely detect and limit the scope of OAuth token abuse by monitoring authentication flows and restricting access to cloud resources based on behavioral analysis.
Control: Zero Trust Segmentation
Mitigation: Identity-aware segmentation policies would likely constrain privilege escalation by limiting compromised account access to specific network segments and reducing visibility into organizational structures across cloud environments.
Control: East-West Traffic Security
Mitigation: Workload-to-workload security controls would likely limit lateral movement by restricting east-west traffic flows between cloud services and preventing unauthorized access to additional organizational resources and mailboxes.
Control: Multicloud Visibility & Control
Mitigation: Unified multicloud monitoring would likely detect and constrain command and control activities by providing visibility across cloud platforms and identifying suspicious communication patterns between compromised infrastructure components.
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely reduce the scope of data exfiltration by monitoring and restricting outbound data flows from compromised cloud workloads and limiting access to sensitive business communications.
Residual business disruption would likely be contained to initially compromised segments rather than spreading across wholesale distribution, construction, financial services, real estate, higher education, and healthcare sectors at scale.
Impact at a Glance
Affected Business Functions
- Email Communications
- Authentication Systems
- Business Email Operations
- Financial Transaction Processing
Estimated downtime: 7 days
Estimated loss: $2,500,000
Compromised authentication tokens for over 12,000 Microsoft 365 accounts across 10,000+ organizations, including access to corporate email communications, wire transfer information, pending invoices, and executive correspondence. Business email compromise campaigns targeting financial transactions and sensitive corporate communications.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to prevent lateral movement between compromised accounts and limit access to high-value organizational resources
- • Deploy Egress Security & Policy Enforcement to block unauthorized data exfiltration and detect suspicious outbound communication patterns to external domains
- • Enable Multicloud Visibility & Control to monitor OAuth token usage patterns and detect anomalous Microsoft Graph API access across cloud environments
- • Utilize Threat Detection & Anomaly Response capabilities to baseline normal authentication flows and alert on device-code authentication abuse patterns
- • Enforce Cloud Firewall (ACF) with URL filtering to block access to known phishing infrastructure and prevent communication with malicious redirect chains



