Home » News » IT » Microsoft Disrupts Phishing Service That Compromised Thousands of Email Inboxes

Microsoft Disrupts Phishing Service That Compromised Thousands of Email Inboxes

Phishing Service

Microsoft Takes Action Against a Growing Phishing Threat

Email remains one of the most valuable targets for cybercriminals because a compromised inbox can provide access to sensitive conversations, business relationships, payment information and internal documents. However, a recent case shows how artificial intelligence can make that access even more dangerous.

Microsoft has disrupted EvilTokens, an AI enabled cybercrime service that was linked to more than 12,000 compromised email inboxes across more than 10,000 organizations worldwide. The company announced the disruption on September 22, 2026, following coordinated legal and operational action with technology companies and law enforcement.

The operation highlights how phishing is evolving from simple credential theft into a broader business model built around automated account compromise and fraud.

How the EvilTokens Service Worked

EvilTokens used device code phishing to trick victims into completing a legitimate authentication process while unknowingly giving attackers access to their accounts. Instead of stealing a password directly, attackers could persuade users to authorize a session controlled by the attacker.

Once an account was compromised, the service provided tools that helped criminals examine the victim’s mailbox. Its AI capabilities could summarize messages, identify financial discussions, map organizational relationships and locate potential targets for fraud.

Microsoft said the service could help attackers identify people involved in payments, vendor relationships and other sensitive business activities. This reduced the amount of manual work required after an inbox was compromised.

AI Made Inbox Analysis Much Faster

Traditionally, criminals who gained access to an email account still needed to spend considerable time searching through messages to understand how an organization operated.

EvilTokens attempted to automate that process. Its AI assistant could analyze large amounts of mailbox information and highlight conversations that could be useful for financial fraud or impersonation.

This is an important change in the cybercrime landscape. Artificial intelligence was not simply being used to write convincing phishing messages. It was being used to help criminals decide who to target and how to exploit relationships inside an organization.

Thousands of Organizations Were Affected

According to Microsoft, EvilTokens emerged in February 2026 and was associated with more than 12,000 compromised inboxes across more than 10,000 organizations worldwide.

Observed victims were concentrated in countries including the United States, Canada, the United Kingdom, Australia, India and France. Affected industries included financial services, healthcare, higher education, construction, real estate and wholesale distribution.

The scale demonstrates why email security should not be treated as an isolated IT concern. A compromised mailbox can create risks for finance, sales, human resources and other business functions.

Microsoft Seized Phishing Infrastructure

Microsoft’s Digital Crimes Unit worked with Health ISAC and several technology and security organizations as part of the disruption. With authorization from a United States federal court, Microsoft and its partners seized 50 websites used to operate the service and disabled more than 150 additional domains connected to its infrastructure.

The United Kingdom also became part of the operation. Microsoft’s collaboration with the Metropolitan Police Service’s cybercrime team contributed to the arrest of two men on suspicion of offenses connected with the alleged operation. Microsoft said both individuals were later released on police bail while the investigation continued.

The action demonstrates how effective cybercrime disruption can require cooperation between technology companies, infrastructure providers and law enforcement.

Device Code Phishing Is Becoming More Important

The EvilTokens case also draws attention to device code authentication attacks. Microsoft has previously reported campaigns that abuse this authentication flow to compromise organizational accounts.

The technique can be effective because victims may believe they are completing a normal sign in process. Meanwhile, attackers attempt to obtain the authentication token associated with their own session. Microsoft researchers say EvilTokens used this approach at scale and could maintain access through stolen tokens and malicious inbox rules.

Therefore, organizations need to monitor unusual authentication activity rather than relying only on password protection.

The Business Impact Can Extend Beyond Email

A compromised inbox can become the starting point for business email compromise, payment fraud and impersonation.

Finance teams may face fraudulent payment requests. Sales teams can become targets through trusted customer relationships. HR teams may encounter impersonation involving employee information. Marketing teams can also be exposed when customer or campaign communications are accessed.

Consequently, cybersecurity now intersects with finance industry updates, HR trends and insights, sales strategies and research and marketing trends analysis. Protecting business communication is increasingly part of protecting the wider organization.

Employees Remain an Important Security Layer

Technology controls can reduce phishing risk, but employees still play an important role. Attackers often rely on urgency, familiarity and trusted communication patterns to persuade users to take action.

Organizations can therefore combine technical protections with practical awareness training. Employees should understand that an apparently legitimate authentication request can still be part of an attack.

Microsoft’s security guidance recommends layered protection that combines technical controls with user awareness, monitoring and threat detection.

AI Is Changing Both Attacks and Defense

The EvilTokens case shows that artificial intelligence can accelerate multiple stages of a cyberattack. At the same time, defenders are also using AI to investigate threats, analyze evidence and identify malicious infrastructure.

Microsoft said its investigators used reverse engineering and AI powered tools during the disruption. This creates a broader technology insight for security teams. AI is becoming part of the defensive process as well as the attack process.

As a result, cybersecurity teams will need to understand how AI affects identity protection, email security, threat detection and incident response.

Valuable Insights for Businesses

The disruption of EvilTokens shows that organizations need to think beyond traditional phishing prevention. Protecting passwords is important, but businesses also need to monitor authentication activity, session tokens, mailbox rules and unusual access patterns.

Furthermore, employees should verify sensitive payment and account requests through trusted communication channels. This is especially important when an attacker already has access to a legitimate mailbox.

The larger lesson is that a compromised inbox can quickly become a business risk when AI helps attackers understand its contents. Strong identity controls, continuous monitoring, employee awareness and rapid incident response can help reduce that risk. For more technology insights and IT industry news, connect with InfoProWeekly for practical coverage of cybersecurity and emerging digital threats.
Stay informed about the technology developments shaping security, business operations and the future of connected organizations.

Tagged: