All stories
Security Worldwide

Microsoft says a phishing kit compromised 12,000-plus inboxes.

EvilTokens can lead people from a phishing message to a real Microsoft sign-in page — and still give an attacker access.

Source

What happened

Microsoft reports that campaigns using the EvilTokens phishing service compromised more than 12,000 inboxes at over 10,000 organizations worldwide. An attacker starts a device-code sign-in and tricks the target into entering that code on Microsoft's legitimate page, authorizing the attacker's session. Microsoft says it and partners disrupted infrastructure used by the service.

SIGNAL / SIGNAL analysis

What changes for you

A genuine Microsoft web address does not prove that the sign-in request is yours. Enter a device code only when you personally started a sign-in on a device you recognize.

What to keep in mind

The victim figures and disruption are Microsoft's findings, not independent SIGNAL measurements. They cover activity since February 2026, not compromises confined to 22 September. Disrupting infrastructure does not establish that all related attacks have ended.

What you can do

If you did not start a device sign-in, do not enter the code. Organizations can restrict device-code sign-in where it is unnecessary and review suspicious sign-ins and mailbox rules.

Source

www.microsoft.com

Company threat research. Company claims are not independent test results.

No correction recorded for this article.

Report an error