Microsoft says a phishing kit compromised 12,000-plus inboxes.
EvilTokens can lead people from a phishing message to a real Microsoft sign-in page — and still give an attacker access.
What happened
Microsoft reports that campaigns using the EvilTokens phishing service compromised more than 12,000 inboxes at over 10,000 organizations worldwide. An attacker starts a device-code sign-in and tricks the target into entering that code on Microsoft's legitimate page, authorizing the attacker's session. Microsoft says it and partners disrupted infrastructure used by the service.
What changes for you
A genuine Microsoft web address does not prove that the sign-in request is yours. Enter a device code only when you personally started a sign-in on a device you recognize.
What to keep in mind
The victim figures and disruption are Microsoft's findings, not independent SIGNAL measurements. They cover activity since February 2026, not compromises confined to 22 September. Disrupting infrastructure does not establish that all related attacks have ended.
What you can do
If you did not start a device sign-in, do not enter the code. Organizations can restrict device-code sign-in where it is unnecessary and review suspicious sign-ins and mailbox rules.
Source
www.microsoft.comCompany threat research. Company claims are not independent test results.
No correction recorded for this article.
Report an error