Jessica Entwistle
September 23 2026
Microsoft has announced the disruption of EvilTokens, a phishing-as-a-service platform that enabled attackers to steal credentials and session tokens from Microsoft 365 accounts using device code phishing techniques. Dark Reading reports that Microsoft seized 50 websites and disabled more than 150 domains as part of a coordinated legal and technical action. EvilTokens provided a turnkey phishing service that allowed less technically skilled attackers to launch sophisticated credential theft campaigns targeting Microsoft 365 users. Device code phishing exploits the legitimate device authentication flow used by Microsoft 365, tricking users into entering a code that grants attackers access to their accounts without needing to steal passwords directly. The disruption of EvilTokens removes a significant enabler of phishing attacks, but similar services are likely to emerge, and the underlying technique remains viable.
For UK organisations using Microsoft 365, this development highlights the ongoing evolution of phishing techniques and the importance of layered defences beyond password security alone. Device code phishing bypasses traditional password protections and can defeat basic multi-factor authentication if users are tricked into approving malicious authentication requests. The fact that EvilTokens operated as a service means that even unsophisticated attackers could launch effective campaigns against Microsoft 365 tenants, lowering the barrier to entry for credential theft attacks. Organisations should ensure that conditional access policies are configured to restrict device registration, that users are trained to recognise device code phishing attempts, and that monitoring is in place to detect unusual authentication patterns or token usage. Microsoft's disruption action is helpful, but it does not eliminate the underlying technique, and organisations remain responsible for configuring their tenants defensively.
Organisations should review Microsoft 365 conditional access policies to ensure that device registration is restricted and that authentication requests are subject to appropriate controls. Security teams should evaluate whether users are trained to recognise device code phishing attempts, which typically involve receiving an unsolicited code and being directed to enter it at a legitimate Microsoft authentication page. Monitoring should be configured to detect unusual authentication patterns, such as authentication requests from unexpected locations, devices, or IP addresses, or token usage that does not match normal user behaviour. This is also a prompt to review whether multi-factor authentication is configured to require approval from a known device or location, rather than simply accepting any authentication request that includes a valid code. Phishing-as-a-service platforms lower the barrier to entry for attackers, and defensive configurations need to account for the fact that these techniques are now widely accessible.
Source: Dark Reading