EvilTokens Phishing Attack: How Cybercriminals Are Bypassing MFA to Compromise Business Email
Microsoft has disrupted a cybercrime platform known as EvilTokens that was used to compromise business email accounts, bypass expected protections from multi-factor authentication and help criminals identify opportunities for financial fraud.
Microsoft disclosed the operation on September 22, 2026, describing EvilTokens as a phishing-as-a-service platform that used device-code phishing, stolen authentication tokens and artificial intelligence to support account compromise and business email fraud.
The campaign is significant because it demonstrates an important limitation in corporate cyber security: multi-factor authentication can substantially reduce account compromise, but it does not eliminate phishing risk.
Attackers are increasingly attempting to steal authenticated sessions and access tokens rather than simply obtaining passwords.
For US organizations, the EvilTokens operation provides another reason to review how authentication, email security and incident response work together as part of a wider Cyber Security strategy.
What Is EvilTokens?
According to Microsoft Threat Intelligence, EvilTokens developed into a major phishing-as-a-service platform used by cybercriminals to target Microsoft 365 accounts.
The platform supported what is known as device-code phishing.
In a legitimate device-code authentication process, a user may be directed to an official Microsoft sign-in page and asked to enter a code to authorize access from another device or application.
Attackers can abuse that process.
Instead of creating a fake Microsoft login page, the criminal persuades the victim to use the genuine Microsoft authentication system and enter a code generated for a session controlled by the attacker.
The user may successfully complete multi-factor authentication believing they are authorizing a legitimate application.
In reality, they may be granting the attacker an authentication token that provides access to the account.
That distinction matters.
Traditional phishing awareness often teaches users to look for suspicious domains or fake login pages. Device-code phishing can be more difficult to identify because part of the authentication process takes place on legitimate infrastructure.
Why MFA Does Not Eliminate Phishing Risk
Multi-factor authentication remains an important security control.
However, organizations should avoid treating MFA as evidence that an account cannot be compromised through phishing.
EvilTokens demonstrates how attackers can target the authentication process itself.
Rather than stealing a password and attempting to defeat a second authentication factor, the attacker attempts to persuade the user to authorize the malicious session.
Once a valid token has been obtained, access may continue while that token remains active.
Microsoft warned that in some circumstances these tokens can also be used to establish access from additional devices, potentially creating persistence within the compromised account.
For businesses, this means that resetting a password may not always be sufficient following a suspected compromise.
An incident response may also need to examine:
- Existing authenticated sessions.
- Active access tokens.
- Recently authorized devices or applications.
- Changes to authentication methods.
- Mailbox forwarding rules.
- Suspicious sign-in activity.
- Unusual Microsoft 365 permissions.
- Access from unfamiliar locations or devices.
Understanding the method used by the attacker can be as important as changing the affected password.
Compromised Email Can Become a Financial-Fraud Opportunity
The EvilTokens operation did not stop at obtaining access to email accounts.
Microsoft says the platform incorporated AI tools capable of analyzing compromised mailboxes and identifying potentially valuable information.
That could include:
- Financial conversations.
- Payment instructions.
- Invoice processes.
- Trusted business relationships.
- Organizational roles.
- Senior decision-makers.
- Employees responsible for approving payments.
- Existing conversations that could be used for impersonation.
The system could then assist criminals in identifying who to target and how a fraudulent message might be made more convincing.
This creates a direct connection between account compromise and business email compromise.
An attacker who has access to a legitimate mailbox may be able to observe how a company communicates before attempting fraud.
They might wait for a genuine invoice conversation, imitate a senior employee or alter payment instructions at a point when the request appears plausible.
That can make fraudulent communications substantially harder to identify than an unsolicited phishing email.
Business Email Compromise Is More Than an Email Problem
Organizations sometimes treat a compromised inbox as an isolated IT issue.
In practice, business email compromise can create wider financial, legal and evidential questions.
A compromised account may have been used to:
- Send fraudulent payment instructions.
- Access confidential attachments.
- Download commercially sensitive information.
- Impersonate executives or employees.
- Contact clients, suppliers or professional advisers.
- Identify future fraud targets.
- Change account or authentication settings.
- Establish persistence within the environment.
Where financial fraud is suspected, businesses may also need to establish when the compromise began and which communications the attacker could access.
Our previous article on Social Engineering Attacks on U.S. Companies examined how attackers can impersonate corporate IT personnel and persuade employees to surrender authentication information.
EvilTokens illustrates a related but distinct development: attackers are industrializing techniques that can abuse legitimate authentication workflows and then automate analysis of the information they obtain.
Warning Signs of Device-Code Phishing
Employees should be cautious when unexpectedly asked to enter a code into an authentication page, even where the webpage itself is legitimate.
Potential warning signs can include:
- An unexpected request to authenticate a device or application.
- An email asking the recipient to enter a device code.
- Claims that authentication is required to view an invoice or shared document.
- An unexpected request associated with an RFP or file-sharing notification.
- Authentication prompts that do not correspond with an action initiated by the user.
- Pressure to complete authentication quickly.
- Sign-in activity associated with an unfamiliar application or device.
Microsoft identified multiple phishing themes used by EvilTokens, including invoices, requests for proposals and shared-file notifications.
Employees therefore need to understand that the presence of a legitimate Microsoft login page does not automatically mean the request that led them there was legitimate.
What Should Organizations Do After a Suspected Account Compromise?
A suspected token or business email compromise should be escalated promptly.
The response should focus on understanding the scope of the incident rather than assuming that changing the password has resolved it.
Appropriate actions may include:
- Securing the affected account.
- Revoking active authentication sessions and tokens where appropriate.
- Reviewing recently authorized devices and applications.
- Examining sign-in and authentication logs.
- Reviewing mailbox forwarding and filtering rules.
- Preserving suspicious emails and authentication messages.
- Determining whether messages, files or attachments were accessed.
- Reviewing outbound messages sent from the account.
- Identifying any suspicious payment instructions.
- Assessing whether other employees received similar phishing attempts.
Where fraudulent payments may have occurred, organizations may also need to coordinate quickly with financial institutions, legal advisers, insurers and other relevant parties.
Evidence should be preserved wherever possible before unnecessary changes are made to affected systems.
Strengthening Defenses Against Modern Phishing
The EvilTokens operation demonstrates why organizations need several layers of protection.
MFA remains valuable, but it should be supported by appropriate access policies, employee awareness, authentication monitoring and incident-response procedures.
Businesses should also consider whether employees understand that phishing can involve legitimate websites and legitimate authentication systems.
Training that focuses only on identifying spelling mistakes or suspicious-looking URLs may not adequately prepare employees for modern social-engineering techniques.
Organizations should establish clear procedures for verifying unexpected authentication requests and provide employees with an easy way to report suspicious activity.
Monitoring should also focus on what happens after authentication.
Unusual sessions, new devices, mailbox changes or atypical access patterns can sometimes provide indicators that an account has been compromised.
Cyber Security Support from Conflict International USA
Conflict International USA supports corporations, law firms, family offices and other organizations dealing with cyber incidents and suspected account compromise.
Our cyber security work can include incident assessment, review of available indicators of compromise, account and access analysis, evidence preservation, cyber threat intelligence and coordination with legal, insurance and technical teams where appropriate.
Where a matter involves both cyber intrusion and suspected financial fraud, understanding the technical compromise alongside the associated communications and payment activity can help establish a clearer picture of what occurred.
No security control can guarantee that every phishing attempt or account compromise will be prevented.
The objective is to reduce exposure, identify suspicious activity quickly and respond with reliable information when an incident occurs.
Organizations concerned about business email compromise, token theft, phishing or another suspected cyber incident can contact Conflict International USA to discuss the circumstances and available response options.