ProBackend
oauth consent phishing
7 hours ago6 min read

AI Cybersecurity Threats 2026: How EvilTokens Turned Phishing Into a Subscription Service

Microsoft's September 2026 takedown of EvilTokens exposed an AI-powered phishing-as-a-service platform that sold device-code phishing and a cybercrime chatbot on Telegram, compromised more than 12,000 Microsoft 365 inboxes, led to a lawsuit with Health-ISAC, and ended with two arrests in the UK.

The Takedown That Exposed Something Bigger

Microsoft disrupted EvilTokens in September 2026, and if you're tracking AI cybersecurity threats in 2026, this takedown is worth understanding. The operation exposed how phishing-as-a-service can combine device-code abuse, automation, and an AI chatbot to help criminals exploit compromised Microsoft 365 accounts at scale — reportedly compromising more than 12,000 inboxes.

What makes the case a landmark is not just the technical trick. It is the business model, and the fact that it ended with handcuffs. Microsoft's Digital Crimes Unit partnered with the health-sector cybersecurity non-profit Health-ISAC on a lawsuit filed in U.S. District Court, using the resulting court authorization to take the platform and its related infrastructure offline. Working alongside the U.K.'s Metropolitan Police Service cybercrime team, that legal pressure led to the arrests of two men — aged 32 and 38 — earlier this month. Both were released on bail while the investigation continues, and Microsoft said the pair were the alleged operators of EvilTokens, while noting that others may have supported the service in various capacities.

How the Service Was Sold: Phishing as a Subscription

EvilTokens was not a piece of malware sold on a dark-web forum. It ran openly on Telegram, and the economics were straightforward: a reported $1,500 initiation fee followed by a recurring $500 monthly subscription. In exchange, paying criminals got a managed service rather than a one-off toolkit.

The platform helped operators compromise accounts, sift through breached and live inboxes to work out what was worth stealing, and identify the best methods for monetizing their access through fraud. Subscribers did not need to be particularly skilled at social engineering or at writing persuasive fraud lures — the attached AI chatbot handled much of that tradecraft, which is why security researchers describe EvilTokens as one of the clearest examples so far of AI-enabled cybercrime offered as a complete, commercial product.

How EvilTokens Used Device-Code Phishing

Device-code authentication is a legitimate sign-in flow, but attackers can abuse it by persuading a victim to enter a code on a real Microsoft page. The victim may believe they are completing a routine verification, while the attacker uses the resulting authorization to access the account. This is an OAuth-related threat: the attacker seeks an access token through a trusted workflow rather than simply stealing a password.

Because the victim is interacting with a genuine Microsoft authentication endpoint, the flow can slip past the instincts users are trained on — check the URL, don't type your password on a strange page. The password never leaves the legitimate page; the attacker simply rides the approval. Surreptitiously gaining this kind of persistent access to compromised Microsoft 365 and Entra ID accounts was the core of the product, and the attached AI chatbot was then used to facilitate business email compromise (BEC) scams from inside those mailboxes.

EvilTokens packaged this approach as a service. The reported takedown described an AI-enabled platform that helped operators manage compromised inboxes and support follow-on fraud. AI can reduce friction for a criminal operator, but it does not change the underlying need to trick a user into approving authentication.

For related context, see Storm-2372 and Microsoft 365 device-code workflows and Greatness PhaaS and OAuth device-code attacks.

Why This Matters for AI Cybersecurity Threats

The EvilTokens case illustrates a broader pattern in artificial intelligence and cybersecurity: AI can make phishing operations easier to operate, personalize, or scale, while familiar identity weaknesses remain central. Security teams should assess the whole authentication journey, not just whether a password was captured.

Two features of this case deserve emphasis for anyone building a 2026 threat model. First, the monetization layer was as automated as the intrusion layer — the chatbot that analyzed stolen mailboxes and drafted fraudulent correspondence lowers the cost of BEC for hundreds of paying customers at once. Second, the service was sold in the open, on Telegram, under a conventional SaaS-style pricing scheme. Law enforcement and platform disruption have historically lagged this kind of brazen commercialization; the arrests in the UK suggest that gap may be closing.

This also informs AI agent security. An AI assistant or agent connected to email or other business tools can have meaningful access, so organizations should limit permissions, monitor authorization events, and review connected applications. The same lesson cuts both ways in the agentic AI era: defenders are rolling out autonomous agents with mailbox and document access, and attackers are attaching AI to stolen access. Governance of non-human authorization — human or machine, internal or vendor-supplied — is now a core part of securing enterprise identity. These controls are useful whether activity is driven by a human operator, automation, or an AI-enabled service.

For a related look at authorization abuse and the limits of login-focused defenses, read Why MFA Fails Against OAuth Consent Abuse in 2026.

  • Restrict device-code authentication where it is not needed, using identity-provider policies appropriate to the organization.
  • Require phishing-resistant multifactor authentication for high-risk users and sensitive workflows.
  • Monitor sign-ins, OAuth grants, unfamiliar applications, and unusual mailbox activity; revoke suspicious sessions and tokens promptly.
  • Alert specifically on mailbox rule creation, forwarding rules, and inbox-delegation changes, which are common tells after a device-code compromise turns into BEC.
  • Train users to treat unexpected sign-in codes and approval requests as suspicious, especially when prompted by unsolicited messages or calls — including phone-based impersonation that walks a victim through approving a code.
  • Review third-party app permissions and apply least privilege to email access and AI-connected services.
  • Maintain an incident response process for compromised accounts, including session revocation, credential resets where appropriate, and mailbox rule review.

No single control is a silver bullet, but treated as a complete program rather than a checklist, these measures are part of sound cybersecurity best practices: reduce unnecessary authorization paths, detect misuse quickly, and make account recovery decisive.

The Broader Lesson

EvilTokens is a reminder that AI is an accelerant, not a substitute for attacker access. The service did not invent device-code phishing, and the AI chatbot did not break anything that had not already been approved by a person. What the AI did was remove skill barriers and operating costs, letting a modest number of operators run a fraud factory for a subscriber base.

The other half of the lesson is offensive in the best sense: a private-sector victim, a legal takedown, a sector information-sharing partner in Health-ISAC, and a national police force produced arrests, not just a domain seizure and a rebuild cycle. Whether that playbook scales to the next AI-powered cybercrime service is the open question for 2026.

For security teams, the practical conclusion is unchanged: harden identity flows, watch the authorization events that legacy tooling ignores, and govern every app or agent with access to business data. Clear policies, monitoring, and practiced response help keep a compromised approval from becoming a broader incident.

the takedown that exposed something bigger

More blogs