Canadian Cyber Security Journal
SOCIAL:
Filed under: Trends

Microsoft-Led Takedown Dismantles an AI-Powered Phishing Service Behind 12,000 Account Compromises

What Happened

Microsoft’s Digital Crimes Unit, working with Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, the Shadowserver Foundation, and TRM Labs, obtained authorization from the US District Court for the Eastern District of Virginia to disrupt EvilTokens, a phishing-as-a-service platform active since February. The service was the first to support device-code authentication phishing at scale, tricking victims into entering an attacker-supplied device code at a legitimate Microsoft sign-in page, which then hands the attacker persistent access tokens under the victim’s identity without ever exposing a password. Microsoft reports the platform used artificial intelligence at every stage of the attack chain, from customizing phishing lures to sorting through compromised inboxes to identify high-value targets, and says EvilTokens compromised more than 12,000 accounts across over 10,000 organizations. London’s Metropolitan Police arrested two men, ages 32 and 38, suspected of administering the service, executing warrants at addresses in Canary Wharf and Nine Elms. Read more from BleepingComputer.

Why This Matters for Canadian Organizations

Device-code phishing bypasses the visual cues most Canadian employees train on, since victims type a code into Microsoft’s own real login page rather than a spoofed site, making it a difficult technique for standard security-awareness training to counter on its own. With Microsoft 365 as the dominant productivity platform across Canadian enterprise and government, and adoption of AI-assisted phishing tooling accelerating criminal operations broadly, this technique is likely to persist even with EvilTokens offline, since device-code flows remain enabled by default in many tenants. The multi-party takedown model, combining a legal court order with cooperation from cloud providers, exchanges, and threat-intelligence firms, offers a template worth citing when Canadian organizations and the Canadian Centre for Cyber Security press for similar coordinated action against services operating outside Canadian jurisdiction.

What to Do

Administrators should review whether device-code authentication remains enabled in their Microsoft 365 tenant and restrict or disable it where the organization has no legitimate need for the flow, particularly for shared devices and command-line sign-ins. Conditional Access policies restricting device-code sign-in to managed devices and known locations reduce exposure significantly, and security teams should train staff to treat any unsolicited request to enter a code on a Microsoft sign-in page as suspicious regardless of how legitimate the surrounding message appears. Organizations should also monitor for unfamiliar sign-in locations and token-refresh patterns following any suspected phishing attempt, since device-code compromises grant attackers standing access rather than a one-time credential.

Enjoy this article? Don’t forget to share.