Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
- ID
- 27377
- Status
- summarized
- Published
- 23 Sep 2026, 1:03 AM
- Fetched
- 23 Sep 2026, 2:56 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/microsoft-takes-down-eviltokens-device.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 7.0
- Created
- 23 Sep 2026, 2:57 AM
- Tags
- Audience
- developersai_agent_userssaas_founders
What happened
Microsoft took down EvilTokens, a phishing-as-a-service platform that compromised 12,000 inboxes by abusing the OAuth 2.0 device authorization flow. The platform used an AI chatbot to analyze victim inboxes, identify trusted relationships and payment patterns, and draft impersonation messages to maximize fraud success. UK police arrested two men (ages 32 and 38) on September 11, 2026; Microsoft tracks the operators as Storm-2992.
Why it matters
If you build or maintain apps using OAuth 2.0 device-code flow (common for CLI tools, IoT, and TV/limited-input devices), this is a concrete attack pattern your users are vulnerable to: attackers phish a device code, get the victim to enter it at the legitimate microsoft.com/devicelogin URL, then receive an authenticated session token without ever touching credentials. Review whether your device-flow implementation has rate limiting, anomaly detection, or user confirmation steps that could detect token replay. The AI-assisted inbox analysis also means compromised tokens now lead to far more targeted BEC-style fraud than simple data exfiltration.
Discussion angle
Walk through the OAuth 2.0 device authorization flow on screen and show exactly where the EvilTokens attack inserts itself — then discuss what mitigations are realistic for Malaysian startups using Microsoft 365 or building device-flow auth, given that the victim enters the code on a legitimate Microsoft page.