The takeaway: Cybercriminals used a subscription service called EvilTokens to steal access to Microsoft accounts and mine victims' inboxes for payment information, internal reporting lines and trusted business contacts. Microsoft said the platform's AI-assisted tools compromised 12,000 customer accounts at 10,000 organizations over several months.

The service, marketed through a Telegram channel, combined device-code phishing with automated analysis of stolen inboxes. Microsoft said it has now disrupted the operation, seizing 50 websites and 150 additional domains through legal action and partner coordination. The Metropolitan Police Service in the United Kingdom also arrested two men on suspicion of offenses linked to the platform.

EvilTokens charged a $1,500 entry fee and $500 a month. Its customers could send phishing emails at scale and direct recipients to fraudulent pages designed to exploit Microsoft's device-code authentication process.

Device-code authentication is an OAuth sign-in method meant for televisions and other devices with limited input options. A user is shown a code on one device and asked to enter it through a browser on another. Once that step is completed, the device is authorized.

EvilTokens used that process to enroll devices controlled by attackers. Microsoft and SpyCloud said phishing links and attachments took victims to pages that ran scripts communicating with Microsoft Entra in real time and generating device codes. The victims were then instructed to enter those codes at Microsoft's legitimate device-login site, granting attackers access to their accounts.

SpyCloud said the platform used Node.js-based automation and dynamic device codes. Those features helped it avoid some detection methods that depend on known patterns, signatures or static phishing infrastructure. EvilTokens also automated much of the work that followed an account takeover.

Microsoft said its AI-style chatbot was central to that work. The chatbot could examine email in compromised accounts and identify trusted contacts, payment approvals, job roles and other details useful in fraud schemes.

The platform could analyze as many as 5,000 emails at one time. It looked for employees authorized to approve large payments, the managers they reported to and the vendors and customers with whom they worked. It could then help users build a believable reason to request a payment or change banking instructions.

Microsoft said EvilTokens could recommend fraud strategies and draft messages that appeared to come from trusted contacts. That reduced the time attackers would normally spend reviewing mail, invoices and contact lists before trying to redirect money.

The compromised accounts belonged to organizations in wholesale distribution, construction, financial services, real estate, higher education and healthcare. Most of the affected accounts belonged to users in the United States, followed by Canada, the United Kingdom, Australia, India and France.

Microsoft said the case illustrates how a stolen mailbox can become an immediate fraud problem rather than simply an account-security issue.

"For organizations, the lesson is: assume that once an inbox is compromised, criminals may understand its contents in minutes, not days," Microsoft said. "Strong identity protections and monitoring remain essential, but organizations should also independently verify requests to change payment information, redirect funds, or approve unusual transactions through a trusted second channel."