September 22, 2026
Microsoft Accounts Taken Over Without Passwords: EvilTokens Compromised 12 000 Mailboxes
On September 22, Microsoft said that EvilTokens was linked to the compromise of more than 12 000 mailboxes across 10 000 organizations. Users entered a code on the real microsoft.com/devicelogin and authorized an attacker's session without revealing their password. Microsoft seized 50 sites and disabled more than 150 domains.

Phishing used to typically steal passwords. EvilTokens asked victims to enter a code on the real Microsoft site, and changing a password might not terminate an already authorized session.
Vibe coding in the attack. Microsoft found signs that much of EvilTokens was built through AI-assisted vibe coding. The platform appeared in February, offered 44 email and landing-page templates, and access was sold through Telegram for $1 500 and $500 per month.
Close the entry point. In Entra ID, Microsoft advises enabling Report-only first, then creating a Conditional Access policy for Device code flow and blocking access for all users and resources. If this phishing scheme is suspected, sessions should be revoked through revokeSign-inSessions and the compromised account temporarily disabled: a standard session revocation can leave an access token active for up to an hour.
The network is already being dismantled. On September 11, British police detained two men, and Microsoft said EvilTokens used capabilities from several AI models.
Microsoft and Health-ISAC filed case No. 1:26-cv-3047 in the Eastern District of Virginia.
