Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
What happened
Microsoft took down EvilTokens, a large-scale device code phishing service linked to compromising over 12,000 email inboxes. The operation used artificial intelligence throughout its attack chain to bypass security measures. The takedown was authorized by the U.S. District Court for the Eastern District of Virginia and involved coordinated efforts from Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, and The Shadowserver Foundation.
The risk
EvilTokens automated phishing attacks, exploiting device code flows to steal account credentials at scale. Using AI in phishing lets attackers more convincingly mimic user interactions and adapt in real time, increasing the likelihood of success. This approach makes traditional defenses like static link scanning and password policies less effective, exposing organizations and users to stealthier credential theft.
Why it matters
This takedown signals that AI is no longer just a tool for defenders or marketers; attackers are integrating it systematically to improve phishing sophistication. Companies must assume phishing attempts could be enhanced with AI that personalizes and automates social engineering techniques. It raises the bar for detection and response teams, pushing enterprises to adopt stronger multifactor authentication and continuous behavioral risk analysis.
Who should pay attention
Security teams, cloud service providers, identity managers, and anyone responsible for email and device security must track this development closely. Companies using device code flows should review their authentication processes, as attackers are exploiting these systems combined with AI to target credentials behind typical multi-step sign-in flows. Investors and executives in cybersecurity platforms should notice how AI arms offenders, increasing demand for adaptive and AI-driven defense tools.
What to watch next
Watch for additional coordinated takedowns as defenders sharpen AI-powered threat intelligence to disrupt evolving phishing schemes. Expect vendors to accelerate integrating AI to detect behavioral anomalies during sign-in and elevate zero-trust implementations. Regulators and courts may also step up enforcement actions against services enabling sophisticated phishing-as-a-service fueled by AI. Defenders tracking phishing KPIs will need to audit for AI-driven attacks and adapt defenses accordingly.
AI Quick Briefs Editorial Desk