Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises

Microsoft has taken down a notorious device-code phishing service called EvilTokens, which was linked to a staggering 12,000 compromised inboxes. This marks a significant victory for the tech giant and its efforts to combat cyber threats. But what exactly is EvilTokens, and why does it matter?

EvilTokens was a sophisticated phishing operation that exploited a vulnerability in two-factor authentication (2FA) systems. Here’s how it worked: when a victim signed up for a new account on a targeted platform, they were prompted to receive a verification code via SMS or email. However, the malicious actors behind EvilTokens had managed to intercept these codes and use them to gain unauthorized access to the victims’ accounts. The service was marketed as a means of automating the process of obtaining device codes, making it easier for attackers to compromise multiple accounts at once.

The phishing operation was tied to 12,000 compromised inboxes across various platforms, highlighting the scale of the threat. Microsoft’s decision to take down EvilTokens is a welcome development, and it underscores the company’s commitment to protecting its users’ security. By disrupting this particular attack vector, Microsoft has significantly reduced the risk of device-code phishing for millions of users.

The takedown also shines a light on the complexities of 2FA systems. Two-factor authentication is designed to provide an additional layer of protection against password cracking and other types of attacks. However, as we’ve seen with EvilTokens, vulnerabilities can exist in even the most seemingly secure systems. Microsoft’s actions demonstrate that tech companies must continually adapt and improve their defenses to stay ahead of evolving threats.

The importance of this development cannot be overstated. With more than 70% of data breaches involving some form of phishing or social engineering attack, it’s clear that human error remains a significant vulnerability in our digital security. By taking down EvilTokens, Microsoft has not only protected its users but also sent a strong message to the cybercrime community: we will not tolerate attacks on our platforms.

So what can individuals do to protect themselves? The most effective way to stay safe is to use robust 2FA methods that go beyond simple SMS or email verification codes. Consider using authenticator apps like Google Authenticator or Microsoft’s own Azure Active Directory, which offer more secure and reliable alternatives. By being proactive about our security, we can reduce the risk of falling victim to these types of attacks.


Source: The Hacker News — 2026-09-22